Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 146/162
3.5
CVE-2022-4559

A vulnerability was found in INEX IPX-Manager up to 6.2.0. It has been declared as problematic. This vulnerability affec

3.5
CVE-2022-4558

A vulnerability was found in Alinto SOGo up to 5.7.1. It has been classified as problematic. This affects an unknown par

3.5
CVE-2022-4556

A vulnerability was found in Alinto SOGo up to 5.7.1 and classified as problematic. Affected by this issue is the functi

3.3
CVE-2022-20562

In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic

3.3
CVE-2022-20559

In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installe

3.3
CVE-2022-20558

In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a per

3.3
CVE-2022-20556

In launchConfigNewNetworkFragment of NetworkProviderSettings.java, there is a possible way for the guest user to add a n

2.3
CVE-2022-20543

In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local

3.3
CVE-2022-20537

In createDialog of WifiScanModeActivity.java, there is a possible way for a Guest user to enable location-sensitive sett

3.3
CVE-2022-20536

In registerBroadcastReceiver of RcsService.java, there is a possible way to change preferred TTY mode due to a missing p

3.3
CVE-2022-20535

In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is in

3.3
CVE-2022-20533

In getSlice of WifiSlice.java, there is a possible way to connect a new WiFi network from the guest mode due to a missin

2.4
CVE-2022-20529

In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass due to a logic error in

3.3
CVE-2022-20528

In findParam of HevcUtils.cpp there is a possible out of bounds read due to a missing bounds check. This could lead to l

3.3
CVE-2022-20526

In CanvasContext::draw of CanvasContext.cpp, there is a possible out of bounds write due to a missing bounds check. This

3.3
CVE-2022-20525

In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package nam

3.3
CVE-2022-20519

In onCreate of AddAppNetworksActivity.java, there is a possible way for a guest user to configure WiFi networks due to a

2.7
CVE-2022-41963

BigBlueButton is an open source web conferencing system. Versions prior to 2.4.3 contain a whiteboard grace period that

2.7
CVE-2022-41962

BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect A

3.5
CVE-2022-4527

A vulnerability was found in collective.task up to 3.0.8. It has been classified as problematic. This affects the functi

3.5
CVE-2022-4526

A vulnerability was found in django-photologue up to 3.15.1 and classified as problematic. Affected by this issue is som

3.5
CVE-2022-4525

A vulnerability has been found in National Sleep Research Resource sleepdata.org up to 58.x and classified as problemati

3.5
CVE-2022-4524

A vulnerability, which was classified as problematic, was found in Roots soil Plugin up to 4.0.x. Affected is the functi

3.5
CVE-2022-4523

A vulnerability, which was classified as problematic, has been found in vexim2. This issue affects some unknown processi

3.5
CVE-2022-4522

A vulnerability classified as problematic was found in CalendarXP up to 10.0.1. This vulnerability affects unknown code.

3.5
CVE-2022-4521

A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown pa

3.5
CVE-2022-4520

A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue

3.5
CVE-2022-4514

A vulnerability, which was classified as problematic, was found in Opencaching Deutschland oc-server3. Affected is an un

3.5
CVE-2022-4513

A vulnerability, which was classified as problematic, has been found in European Environment Agency eionet.contreg. This

3.5
CVE-2022-4495

A vulnerability, which was classified as problematic, has been found in collective.dms.basecontent up to 1.6. This issue

3.5
CVE-2022-4456

A vulnerability has been found in falling-fruit and classified as problematic. This vulnerability affects unknown code.

3.5
CVE-2022-4455

A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index

2.7
CVE-2022-46143

Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an u

3.3
CVE-2022-45484

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <

3.3
CVE-2022-41288

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <

3.3
CVE-2022-41287

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <

3.3
CVE-2022-41280

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <

3.3
CVE-2022-41279

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <

3.3
CVE-2022-41278

A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions <

3.3
CVE-2022-31699

VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox

2.3
CVE-2022-20240

In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a miss

3.5
CVE-2022-4444

A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unkn

3.5
CVE-2022-4421

A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of t

2.6
CVE-2021-4244

A vulnerability classified as problematic has been found in yikes-inc-easy-mailchimp-extender Plugin up to 6.8.5. This a

3.8
CVE-2022-37911

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A

3.5
CVE-2022-45228

Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page.

3.5
CVE-2022-4401

A vulnerability was found in pallidlight online-course-selection-system. It has been classified as problematic. Affected

3.5
CVE-2022-4400

A vulnerability was found in zbl1996 FS-Blog and classified as problematic. This issue affects some unknown processing o

3.5
CVE-2022-4396

A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option o

3.5
CVE-2022-4377

A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerabili

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started