Nsasoft develops a narrow portfolio of system-auditing and file-management utilities, including products such as NSAuditor, SpotAuditor, and Product Key Explorer, that operate at the host level with direct access to memory and system resources. The vendor's vulnerability profile centers on memory-safety weakness classes, particularly classic buffer overflows, stack-based buffer overflows, out-of-bounds writes, and improper memory-buffer handling, which are characteristic of native-code utilities that parse system data and file structures. A meaningful share of the vendor's disclosures reach serious severity, reflecting the privileged execution context and direct memory access that these tools require. Defenders should treat this vendor's advisories as relevant to environments where these system-assessment tools are deployed, particularly in administrative and security-audit workflows; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nsasoft over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-47814HIGH NBMonitor 1.6.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the registration code input field. Attackers can paste a 25 | Jan 16, 2026 | 7.5 | 30 | NO | NO |
CVE-2018-25213HIGH Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the | Mar 26, 2026 | 8.4 | 29 | NO | NO |
CVE-2020-37119CRITICAL Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can cr | Feb 5, 2026 | 9.8 | 29 | NO | NO |
CVE-2019-25434HIGH SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name | Feb 20, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-37212HIGH SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-characte | Feb 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-37211HIGH SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can gener | Feb 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-37210HIGH SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer | Feb 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-37208HIGH SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character | Feb 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-37207HIGH SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-charac | Feb 11, 2026 | 7.5 | 26 | NO | NO |
CVE-2020-37206HIGH ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-ch | Feb 11, 2026 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nsasoft.
Media articles that mention a CVE ID that affects a product developed by Nsasoft — matched by CVE ID, not by vendor name.