Nexryai operates a focused product line centered on the Nexkey authentication and access-control platform, with observed vulnerability patterns clustering around authentication bypass, input validation, and authorization-enforcement mechanisms. The structural weaknesses reflect the critical role of identity and access decisions in such systems, where flaws can propagate across downstream applications relying on the platform. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nexryai over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52077CRITICAL Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and mo | Dec 27, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-49095HIGH nexkey is a microblogging platform. Insufficient validation of ActivityPub requests received in inbox could allow any user to impersonate another user in certain circumstances. Thi | Nov 30, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-43805HIGH Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow users to bypass authentication for | Oct 4, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nexryai.
Media articles that mention a CVE ID that affects a product developed by Nexryai — matched by CVE ID, not by vendor name.