Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gonitro

First CVE: Feb 10, 2017Active for: 9 yearsTotal CVEs: 35
54.7
VTI Score
TOP TARGET

Gonitro maintains a narrowly focused portfolio of PDF creation, editing, and viewing applications—Nitro Pro, Nitro PDF Pro, Nitro Reader, and related products—that serve both enterprise and consumer audiences. Despite the modest product count, the vendor's presence in the vulnerability landscape reflects the widespread deployment of these applications and the complexity of PDF parsing and rendering. The recurring weakness classes affecting this vendor—out-of-bounds writes, use-after-free conditions, heap-based buffer overflows, integer overflows, and NULL pointer dereferences—are characteristic of memory-safety challenges in native PDF processing engines. Public exploit code has emerged for several of this vendor's vulnerabilities, underscoring the appeal of PDF readers as attack vectors for document-based exploitation. Defenders should monitor Gonitro's updates for its PDF products and prioritize patching where these applications handle untrusted documents; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
35
Total CVEs
More Total CVEs than 98% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gonitro over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 10, 2017
9 years ago
Most Recent CVE
Apr 13, 2026
102 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (35 CVEs).

35 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7442HIGH
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.
Aug 3, 20178.871NOYES
CVE-2020-6146HIGH
An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the st
Sep 16, 20208.863NONO
CVE-2020-6113HIGH
An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When process
Sep 17, 20207.856NONO
CVE-2020-6074HIGH
An exploitable code execution vulnerability exists in the PDF parser of Nitro Pro 13.9.1.155. A specially crafted PDF document can cause a use-after-free which can lead to remote c
May 18, 20208.842NONO
CVE-2020-6092HIGH
An exploitable code execution vulnerability exists in the way Nitro Pro 13.9.1.155 parses Pattern objects. A specially crafted PDF file can trigger an integer overflow that can lea
May 18, 20207.840NONO
CVE-2021-21797HIGH
An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stor
Oct 18, 20217.832NONO
CVE-2021-21796HIGH
An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a docu
Oct 18, 20217.832NONO
CVE-2021-21798HIGH
An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to g
Sep 15, 20217.832NONO
CVE-2020-6116HIGH
An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors fr
Sep 17, 20207.832NONO
CVE-2017-7950MEDIUM
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX file.
Jul 7, 20175.530NOYES
View all 35 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products35 CVEs
23%
77%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local25 (71.4%)
Network10 (28.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (20.0%)
Unknown0 (0.0%)
Required28 (80.0%)
Privileges Required
Low1 (2.9%)
High0 (0.0%)
None34 (97.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (35 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.9% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gonitro.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gonitro — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gonitro's Products

View all 2 CNAs →

Top CWEs