Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access pas
Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access passwo
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access u
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILT
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission se
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected v
Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can caus
An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other u
An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other us
An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other
Microsoft Intune Portal for iOS Security Feature Bypass Vulnerability
Media Foundation Information Disclosure Vulnerability
Nextcloud talk is a self hosting messaging service. In versions prior to 12.3.0 the Nextcloud Android Talk application d
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM
JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager ve
Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirec
A improper input validation in Fortinet FortiGate version 6.4.3 and below, version 6.2.5 and below, version 6.0.11 and b
Sensitive information disclosure discovered in wpDiscuz WordPress plugin (versions <= 7.3.11).
The AnyComment WordPress plugin before 0.2.18 is affected by a race condition when liking/disliking a comment/reply, whi
The Duplicate Page or Post WordPress plugin before 1.5.1 does not have any authorisation and has a flawed CSRF check in
Cosign provides container signing, verification, and storage in an OCI registry for the sigstore project. Prior to versi
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroS
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroS
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroS
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroS
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroS
snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions.
IBM Maximo Anywhere 7.6.4.0 applications could allow obfuscation of the application source code. IBM X-Force ID: 161494.
The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high
The Ibtana WordPress plugin before 1.1.4.9 does not have authorisation and CSRF checks in the ive_save_general_settings
An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system di
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attacker
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access me
An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Relea
PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attacker
A stored cross site scripting have been identified at the comments in the report creation due to an obsolote version of
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows tha
The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a public
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
Full list of recipients from customer users in a contact field could be disclosed in notification emails event when the
OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular
An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag,
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessin
Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server ex
Configuration vulnerability in Hitachi Energy LinkOne application due to the lack of HTTP Headers, allows an attacker th
Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and re
Frequently Asked Questions
What does LOW severity mean for CVEs?
CVSS 0.1–3.9 — low-impact vulnerabilities with limited exploitability or minimal consequences
How many low severity CVEs exist?
There are 15,415 CVE records rated LOW in our database. Of these, 6 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize low severity vulnerabilities?
LOW severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect LOW Vulnerabilities
CyberStrike scans your infrastructure and detects low severity vulnerabilities in real time.
Get Started