Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

LOW Severity CVEs

CVSS 0.1 – 3.9

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

15,415
Total
6
Known Exploited
Showing 8,080 of 15,415 total · Page 153/162
3.3
CVE-2022-20310

In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check.

3.3
CVE-2022-20309

In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to

3.3
CVE-2022-20307

In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due

3.3
CVE-2022-20305

In ContentService, there is a possible disclosure of available account types due to a missing permission check. This cou

3.3
CVE-2022-20280

In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lea

3.3
CVE-2022-20267

In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing pe

3.3
CVE-2022-20262

In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. T

2.3
CVE-2022-20261

In LocationManager, there is a possible way to get location information due to a missing permission check. This could le

3.3
CVE-2022-20257

In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the

3.3
CVE-2022-20252

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s

3.3
CVE-2022-20251

In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to si

3.3
CVE-2022-20249

In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to si

2.4
CVE-2022-20245

In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value.

3.3
CVE-2022-20241

In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This

3.5
CVE-2022-2773

A vulnerability was found in SourceCodester Apartment Visitor Management System. It has been classified as problematic.

3.5
CVE-2022-2769

A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue a

3.5
CVE-2022-2768

A vulnerability classified as problematic was found in SourceCodester Library Management System. This vulnerability affe

3.5
CVE-2022-2767

A vulnerability classified as problematic has been found in SourceCodester Online Admission System. This affects an unkn

3.5
CVE-2022-2748

A vulnerability was found in SourceCodester Simple Online Book Store System. It has been classified as problematic. Affe

3.1
CVE-2022-30629

Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker

3.3
CVE-2022-20358

In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content provide

3.2
CVE-2022-38133

In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

3.5
CVE-2022-2725

A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issu

3.5
CVE-2022-2701

A vulnerability classified as problematic was found in SourceCodester Simple E-Learning System. This vulnerability affec

3.5
CVE-2022-2692

A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affe

3.5
CVE-2022-2691

A vulnerability, which was classified as problematic, has been found in SourceCodester Wedding Hall Booking System. Affe

3.5
CVE-2022-2690

A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vuln

3.5
CVE-2022-2689

A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an u

3.5
CVE-2022-2686

A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an

3.5
CVE-2022-2685

A vulnerability was found in SourceCodester Interview Management System 1.0 and classified as problematic. This issue af

3.5
CVE-2022-2684

A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as problematic.

3.5
CVE-2022-2683

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Food Ordering System 1.0. This

3.5
CVE-2022-2682

A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce Syste

3.5
CVE-2022-2681

A vulnerability classified as problematic was found in SourceCodester Online Student Admission System. Affected by this

3.3
CVE-2022-36835

Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to acces

3.3
CVE-2022-36834

Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access

3.3
CVE-2022-33726

Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activit

3.3
CVE-2022-33724

Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers t

2.4
CVE-2022-33720

Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chro

2.3
CVE-2022-33716

An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitial

2.2
CVE-2022-2534

An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starti

3.5
CVE-2022-2499

An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions startin

2.7
CVE-2022-2459

An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 1

3.5
CVE-2022-2307

A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starti

3.7
CVE-2022-33968

In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a

3.1
CVE-2022-31119

Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail wou

2.1
CVE-2022-31120

Nextcloud server is an open source personal cloud solution. The audit log is used to get a full trail of the actions whi

3.5
CVE-2022-2646

A vulnerability, which was classified as problematic, was found in SourceCodester Online Admission System. Affected is a

3.5
CVE-2022-2645

A vulnerability has been found in SourceCodester Garage Management System and classified as problematic. Affected by thi

3.3
CVE-2022-37394

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutr

Frequently Asked Questions

What does LOW severity mean for CVEs?

CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences

How many low severity CVEs exist?

There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize low severity vulnerabilities?

LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.

Detect LOW Vulnerabilities

CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.

Get Started