Nicehash develops mining software and tooling, with a footprint concentrated in the Miner and QuickMiner products used for cryptocurrency mining operations. The recurring vulnerability classes center on resource-management issues such as unbounded allocation, unsafe code delivery mechanisms, error handling that leaks sensitive data, and missing authorization checks, reflecting the trust and operational-isolation boundaries inherent to mining applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicehash over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56513CRITICAL NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of intercepting or redirecting traffic to th | Sep 30, 2025 | 9.8 | 32 | NO | NO |
CVE-2019-6120HIGH An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address allows remote attackers to submit a large number of email add | Nov 6, 2019 | 7.5 | 23 | NO | NO |
An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access to a miner's information about such as his recent payments, u | Nov 6, 2019 | 3.7 | 16 | NO | NO |
A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NOT EXIST" error message occurs whenever a submitted email add | Nov 6, 2019 | 3.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicehash.
Media articles that mention a CVE ID that affects a product developed by Nicehash — matched by CVE ID, not by vendor name.