In Telecomm, there is a possible disclosure of registered self managed phone accounts due to a missing permission check.
In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to
In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due
In ContentService, there is a possible disclosure of available account types due to a missing permission check. This cou
In MMSProvider, there is a possible read of protected data due to improper input validationSQL injection. This could lea
In bluetooth, there is a possible way to enable or disable bluetooth connection without user consent due to a missing pe
In ActivityManager, there is a possible way to check another process's capabilities due to a missing permission check. T
In LocationManager, there is a possible way to get location information due to a missing permission check. This could le
In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the
In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to si
In LocaleManager, there is a possible way to determine whether an app is installed, without query permissions, due to si
In WindowManager, there is a possible method to create a recording of the lock screen due to an insecure default value.
In Messaging, there is a possible way to attach a private file to an SMS message due to improper input validation. This
A vulnerability was found in SourceCodester Apartment Visitor Management System. It has been classified as problematic.
A vulnerability, which was classified as problematic, has been found in SourceCodester Company Website CMS. This issue a
A vulnerability classified as problematic was found in SourceCodester Library Management System. This vulnerability affe
A vulnerability classified as problematic has been found in SourceCodester Online Admission System. This affects an unkn
A vulnerability was found in SourceCodester Simple Online Book Store System. It has been classified as problematic. Affe
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker
In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content provide
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
A vulnerability was found in SourceCodester Company Website CMS. It has been rated as problematic. Affected by this issu
A vulnerability classified as problematic was found in SourceCodester Simple E-Learning System. This vulnerability affec
A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Hall Booking System. This affe
A vulnerability, which was classified as problematic, has been found in SourceCodester Wedding Hall Booking System. Affe
A vulnerability classified as problematic was found in SourceCodester Wedding Hall Booking System. Affected by this vuln
A vulnerability classified as problematic has been found in SourceCodester Wedding Hall Booking System. Affected is an u
A vulnerability, which was classified as problematic, was found in oretnom23 Fast Food Ordering System. This affects an
A vulnerability was found in SourceCodester Interview Management System 1.0 and classified as problematic. This issue af
A vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as problematic.
A vulnerability, which was classified as problematic, was found in SourceCodester Simple Food Ordering System 1.0. This
A vulnerability, which was classified as problematic, has been found in SourceCodester Alphaware Simple E-Commerce Syste
A vulnerability classified as problematic was found in SourceCodester Online Student Admission System. Affected by this
Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to acces
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access
Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activit
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers t
Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chro
An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitial
An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starti
An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions startin
An issue has been discovered in GitLab EE affecting all versions before 15.0.5, all versions starting from 15.1 before 1
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starti
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a
Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions of Nextcloud mail wou
Nextcloud server is an open source personal cloud solution. The audit log is used to get a full trail of the actions whi
A vulnerability, which was classified as problematic, was found in SourceCodester Online Admission System. Affected is a
A vulnerability has been found in SourceCodester Garage Management System and classified as problematic. Affected by thi
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutr
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started