Lucysecurity develops security-awareness training and educational products focused on human-factor vulnerability reduction. The vendor's disclosed issues center on OS command-injection weaknesses in its awareness platform, reflecting risks inherent to applications that process user input or administrative commands. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lucysecurity over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28132CRITICAL LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (in the Support section) allows upload of .php files within a | Mar 11, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lucysecurity.
Media articles that mention a CVE ID that affects a product developed by Lucysecurity — matched by CVE ID, not by vendor name.