Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 121/162
3.3
CVE-2023-45816

Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version

3.3
CVE-2023-5543

When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the

3.3
CVE-2023-5551

Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other gr

3.3
CVE-2023-5549

Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a par

3.3
CVE-2023-5548

Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection.

3.3
CVE-2023-5547

The course upload preview contained an XSS risk for users uploading unsafe data.

3.3
CVE-2023-5545

H5P metadata automatically populated the author with the user's username, which could be sensitive information.

3.3
CVE-2023-5542

Students in "Only see own membership" groups could see other students in the group, which should be hidden.

3.3
CVE-2023-5541

The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content.

2.4
CVE-2023-47616

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Telit Cinterion BGS5, Teli

3.3
CVE-2023-47615

A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS

3.5
CVE-2023-41270

Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-

3.1
CVE-2023-46737

Cosign is a sigstore signing tool for OCI containers. Cosign is susceptible to a denial of service by an attacker contro

3.5
CVE-2021-4431

A vulnerability classified as problematic has been found in msyk FMDataAPI up to 22. Affected is an unknown function of

3.3
CVE-2023-42542

Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID

3.5
CVE-2019-25156

A vulnerability classified as problematic was found in dstar2018 Agency up to 61. Affected by this vulnerability is an u

3.5
CVE-2023-5901

Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

3.5
CVE-2023-5900

Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

3.3
CVE-2023-5748

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VP

3.5
CVE-2023-4700

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 1

3.1
CVE-2023-5963

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to

3.7
CVE-2023-5831

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions start

3.5
CVE-2021-4430

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknow

3.5
CVE-2017-20187

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as proble

3.5
CVE-2023-5930

A vulnerability was found in Campcodes Simple Student Information System 1.0. It has been declared as problematic. This

3.1
CVE-2023-5035

A vulnerability has been identified in PT-G503 Series firmware versions prior to v5.2, where the Secure attribute for se

3.1
CVE-2023-4217

A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session cookies attribute is not

2.4
CVE-2023-5917

A vulnerability, which was classified as problematic, has been found in phpBB up to 3.3.10. This issue affects the funct

2.9
CVE-2023-5920

Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for ot

3.1
CVE-2023-5876

Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enro

3.7
CVE-2023-5875

Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi

2.6
CVE-2023-5910

A vulnerability was found in PopojiCMS 2.0.1 and classified as problematic. This issue affects some unknown processing o

2.7
CVE-2023-2622

Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the

2.7
CVE-2023-37833

Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits tha

3.5
CVE-2023-43295

Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a lo

3.3
CVE-2023-5862

Missing Authorization in GitHub repository hamza417/inure prior to Build95.

3.7
CVE-2023-46138

JumpServer is an open source bastion host and maintenance security audit system that complies with 4A specifications. Pr

3.1
CVE-2023-42804

BigBlueButton is an open-source virtual classroom. BigBlueButton prior to version 2.6.0-beta.1 has a path traversal vuln

3.5
CVE-2023-41891

FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. Prior

3.3
CVE-2023-21349

In Package Manager, there is a possible way to determine whether an app is installed, without query permissions, due to

3.3
CVE-2023-21348

In Window Manager, there is a possible way to determine whether an app is installed, without query permissions, due to s

3.3
CVE-2023-21346

In the Device Idle Controller, there is a possible way to determine whether an app is installed, without query permissio

3.3
CVE-2023-21345

In Game Manager Service, there is a possible way to determine whether an app is installed, without query permissions, du

2.1
CVE-2023-42431

Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbi

3.5
CVE-2023-5837

A vulnerability classified as problematic was found in AlexanderLivanov FotosCMS2 up to 2.4.3. This vulnerability affect

3.5
CVE-2023-5835

A vulnerability classified as problematic was found in hu60t hu60wap6. Affected by this vulnerability is the function ma

3.8
CVE-2023-5834

HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, int

3.3
CVE-2023-40138

In FillUi of FillUi.java, there is a possible way to view another user's images due to a confused deputy. This could lea

3.3
CVE-2023-40137

In multiple functions of DialogFillUi.java, there is a possible way to view another user's images due to a confused depu

3.3
CVE-2023-40136

In setHeader of DialogFillUi.java, there is a possible way to view another user's images due to a confused deputy. This

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started