CVE-2019-16252: Nutfind

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.

Affected products

  • Nutfind Nutfind: up to and including 3.9.12

Published 2020-06-12. Last modified 2026-06-17.