Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via bri
Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned
Keystone is an open source headless CMS for Node.js — built with GraphQL and React. When `ui.isAccessAllowed` is set as
A vulnerability was found in phpRecDB 1.3.1. It has been rated as problematic. Affected by this issue is some unknown fu
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.4 and iPadOS 1
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Ventura 13. A shortcut may be able
In multiple locations, there is a possible way to obscure the microphone privacy indicator due to a logic error in the c
In multiple locations, there is a possible way to retrieve sensor data without permissions due to a permissions bypass.
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row secu
Mattermost fails to delete the attachments when deleting a message in a thread allowing a simple user to still be able t
Out-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may a
Out-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may al
Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledg
Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticate
Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0.
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred whi
When the app is put to the background and the user goes to the task switcher of iOS, the app snapshot is not blurred whi
If certain App Transport Security (ATS) settings are set in a certain manner, insecure loading of web content can be ach
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prio
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prio
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version
user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0
Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access down
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin p
"FFRI yarai", "FFRI yarai Home and Business Edition" and their OEM products handle exceptional conditions improperly, wh
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzo
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumente
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknow
A vulnerability was found in mooSocial mooTravel 3.1.8 and classified as problematic. Affected by this issue is some unk
A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability
A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. Affected is an unknown func
A vulnerability was found in DedeBIZ 6.2.10. It has been rated as problematic. Affected by this issue is some unknown fu
A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some u
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such
A missing Brute-Force protection in CODESYS Development System prior to 3.5.19.20 allows a local attacker to have unlimi
A vulnerability, which was classified as problematic, was found in Cute Http File Server 2.0. This affects an unknown pa
A vulnerability has been found in PHP Jabbers Availability Booking Calendar 5.0 and classified as problematic. Affected
Bluetens Electrostimulation Device BluetensQ device app version 4.3.15 is vulnerable to Man-in-the-middle attacks in the
IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insuffic
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by th
Attackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability t
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting fr
Inappropriate implementation in Omnibox in Google Chrome prior to 99.0.4844.51 allowed an attacker in a privileged netwo
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started