CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25434MEDIUM | SpotAuditor 5.3.1.0 Denial of Service via Registration Name FieldSpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field during registration to trigger an unhandled exception that crashes the application. CWE-121Feb 20, 2026 | CVSS6.7v4.0 | EPSS0.303% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25340MEDIUM | SpotAuditor 5.3.2 - 'Base64' Denial Of ServiceSpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attackers can generate a malformed input file with 2000 repeated characters to trigger an application crash when pasted into the Base64 Encrypted Password field. CWE-121Feb 12, 2026 | CVSS6.7v4.0 | EPSS0.422% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25336HIGH | SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system. CWE-121Feb 12, 2026 | CVSS8.4v4.0 | EPSS0.211% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25334MEDIUM | Product Key Explorer 4.2.0.0 - 'Name' Denial of ServiceProduct Key Explorer 4.2.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by overflowing the registration name input field. Attackers can create a specially crafted text file with repeated characters to trigger a buffer overflow when pasted into the registration name field, causing the application to crash. CWE-121Feb 12, 2026 | CVSS6.7v4.0 | EPSS0.19% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37212MEDIUM | SpotMSN 2.4.6 - 'Name' Denial of ServiceSpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.28% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37211MEDIUM | SpotIM 2.2 - 'Name' Denial Of ServiceSpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.28% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37210MEDIUM | SpotIE 2.9.5 - 'Key' Denial of ServiceSpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.28% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37209MEDIUM | SpotFTP FTP Password Recovery 3.0.0.0 - 'Name' Denial of ServiceSpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.31% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37208MEDIUM | SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of ServiceSpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service. CWE-787Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.41% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37207MEDIUM | SpotDialup 1.6.7 - 'Key' Denial of ServiceSpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.369% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37206MEDIUM | ShareAlarmPro Advanced Network Access Control - 'Key' Denial of ServiceShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash when pasted into the registration key field. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.369% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37205MEDIUM | RemShutdown 2.9.0.0 - 'Name' Denial of ServiceRemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.383% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37203MEDIUM | Office Product Key Finder 1.5.4 - Denial of ServiceOffice Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.333% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37202MEDIUM | NetworkSleuth 3.0.0.0 - 'Key' Denial of ServiceNetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.333% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37201MEDIUM | NetShareWatcher 1.5.8.0 - 'Name' Denial Of ServiceNetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.345% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37200MEDIUM | NetShareWatcher 1.5.8.0 - 'Key' Denial of ServiceNetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an application crash. CWE-121Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.345% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37199MEDIUM | NBMonitor 1.6.6.0 - 'Key' Denial of ServiceNBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.441% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37197MEDIUM | Dnss Domain Name Search Software - 'Name' Denial of ServiceDnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.441% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37196MEDIUM | Dnss Domain Name Search Software - 'Key' Denial of ServiceDnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.441% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37195MEDIUM | BlueAuditor 1.7.2.0 - 'Name' Denial of ServiceBlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.304% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37194MEDIUM | Backup Key Recovery Recover Keys Crashed Hard Disk Drive 2.2.5 - 'Key' Denial of ServiceBackup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by supplying an overly long registration key. Attackers can generate a 1000-character payload file and paste it into the registration key field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.317% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37188MEDIUM | SpotOutlook 1.2.6 - 'Name' Denial of ServiceSpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.394% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37187MEDIUM | SpotDialup 1.6.7 - 'Name' Denial of ServiceSpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.394% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37185MEDIUM | Backup Key Recovery 2.2.5 - 'Name' Denial of ServiceBackup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.304% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37180MEDIUM | GTalk Password Finder 2.2.1 - 'Key' Denial of ServiceGTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash. CWE-120Feb 11, 2026 | CVSS4.6v4.0 | EPSS0.282% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |