In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the ba
Server Side Request Forgery (SSRF) vulnerability in All in One SEO Pro plugin <= 4.2.5.1 on WordPress.
A Drag and Drop spoof vulnerability was discovered in F-Secure SAFE Browser for Android and iOS version 19.0 and below.
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape th
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated
IBM Robotic Process Automation for Cloud Pak 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to exposure of th
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6
Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentic
Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requ
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's settings
In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive
GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that pr
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown fu
A vulnerability, which was classified as problematic, was found in Webmin 2.001. Affected is an unknown function of the
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. Affected by this iss
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on.
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0,
An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.
A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and belo
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in macOS Bi
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16, iOS 15.7 an
A logic issue was addressed with improved state management. This issue is fixed in iOS 16, macOS Ventura 13, watchOS 9.
This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with phy
This issue was addressed with improved entitlements. This issue is fixed in iOS 16, watchOS 9. An app may be able to rea
A vulnerability was found in eolinker apinto-dashboard and classified as problematic. This issue affects some unknown pr
A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unkn
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 12.9.8, all versions starting fr
Auth. (editor+) Reflected Cross-Site Scripting (XSS) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Ne
A vulnerability classified as problematic was found in SourceCodester Online Medicine Ordering System 1.0. Affected by t
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file acti
A vulnerability, which was classified as problematic, was found in SourceCodester Sanitization Management System 1.0. Af
A vulnerability, which was classified as problematic, has been found in SourceCodester Sanitization Management System 1.
A firmware update vulnerability exists in the sysupgrade functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-c
Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeratio
jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prio
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_ino
** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is t
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function ni
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function jl
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy
A vulnerability was found in Linux Kernel. It has been rated as problematic. This issue affects some unknown processing
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function l2
On specific hardware platforms, on BIG-IP versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1,
A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automa
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started