Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to acce
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access icc
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022
In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the
Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable e
An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to othe
An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to o
JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific
An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting fr
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting f
An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, an
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0
An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15
Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15
In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is
A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the f
A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unk
A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability
A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown functi
A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown proces
A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknow
A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part.
A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the f
A flaw was found in PackageKit in the way some of the methods exposed by the Transaction interface examines files. This
The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insuffi
A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an un
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-leve
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the
A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some
A vulnerability was found in SourceCodester Library Management System 1.0. It has been declared as problematic. Affected
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic erro
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by an
A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by th
A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknow
A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects so
A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnera
A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some un
A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. A
A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an un
A vulnerability, which was classified as problematic, was found in Elefant CMS 1.3.12-RC. This affects an unknown part o
A vulnerability, which was classified as problematic, has been found in Elefant CMS 1.3.12-RC. Affected by this issue is
drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency
A vulnerability was found in weblizar User Login Log Plugin 2.2.1. It has been classified as problematic. Affected is an
A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unkno
A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been rated as problematic. Affected by this
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started