Niceforyou's vulnerability footprint centers on access-control and audio-visual infrastructure products, including Linear Emerge E3 systems and Gefen devices, where the observed weakness classes reflect typical web-application and authentication attack surfaces such as cross-site scripting, command injection, SQL injection, and session fixation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Niceforyou over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38627CRITICAL Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt paramet | Jan 3, 2023 | 9.8 | 44 | NO | YES |
CVE-2022-46381MEDIUM Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-0 | Dec 13, 2022 | 6.1 | 32 | NO | YES |
CVE-2022-38628MEDIUM Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which | Dec 13, 2022 | 6.1 | 22 | NO | NO |
CVE-2025-25504MEDIUM An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with network access to connect to the device over | May 5, 2025 | 6.5 | 20 | NO | NO |
CVE-2022-42710MEDIUM Nice (formerly Nortek) Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e devices are vulnerable to Stored Cross-Site Scripting (XSS). | Jan 3, 2023 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Niceforyou.
Media articles that mention a CVE ID that affects a product developed by Niceforyou — matched by CVE ID, not by vendor name.