A vulnerability was found in INEX IPX-Manager up to 6.2.0. It has been declared as problematic. This vulnerability affec
A vulnerability was found in Alinto SOGo up to 5.7.1. It has been classified as problematic. This affects an unknown par
A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the functi
In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic
In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installe
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a per
In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a n
In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local
In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive sett
In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing p
In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is in
In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missin
In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in
In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to l
In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This
In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package nam
In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a
BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect A
A vulnerability was found in collective.task up to 3.0.8. It has been classified as problematic. This affects the functi
A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is som
A vulnerability has been found in National Sleep Research Resource sleepdata.org up to 58.x and classified as problemati
A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. Affected is the functi
A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processi
A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code.
A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown pa
A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue
A vulnerability, which was classified as problematic, was found in Opencaching Deutschland oc-server3. Affected is an un
A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This
A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue
A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code.
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an u
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <
VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a miss
A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unkn
A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of t
A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This a
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A
Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page.
A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected
A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing o
A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option o
A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerabili
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started