Luca App is a contact-tracing and check-in application with a narrow, single-product footprint that achieved above-typical visibility during its operational period. Its limited vulnerability record does not establish a durable weakness-class pattern; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Luca App over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33840HIGH The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digita | Jun 4, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-33839HIGH Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused | Jun 4, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-33838HIGH Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after request | Jun 4, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Luca App.
Media articles that mention a CVE ID that affects a product developed by Luca App — matched by CVE ID, not by vendor name.