Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access acc
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read i
Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access int
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data
The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is
IBM Planning Analytics Local 2.0 allows web pages to be stored locally which can be read by another user on the system.
Nextcloud Password Policy is an app that enables a Nextcloud server admin to define certain rules for passwords. Prior t
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version
Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted p
An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the cont
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This fla
Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific p
mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection
The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perfo
A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue
A vulnerability classified as problematic was found in SourceCodester Simple Task Managing System. This vulnerability af
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contai
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a nul
A Denial-of-Service (DoS) vulnerability was discovered in F-Secure & WithSecure products whereby the aerdl unpack functi
A vulnerability classified as problematic has been found in ConsoleTVs Noxen. Affected is an unknown function of the fil
Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permi
A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problemati
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename'
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated u
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer
In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially
A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This af
A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this
A vulnerability has been found in SourceCodester Simple and Nice Shopping Cart Script and classified as problematic. Aff
A vulnerability classified as problematic has been found in SourceCodester Guest Management System. This affects an unkn
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, passwo
In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could le
In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing
In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration.
In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input v
In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to
In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a miss
In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing
In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. T
In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission che
In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a mi
In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to
In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to
In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could l
In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check.
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started