Spotauditor
Vendor:
First CVE: Nov 2, 2021 · Active for 4 years
6
Total CVEs
More Total CVEs than 83% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spotauditor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2021
4 years ago
Most Recent CVE
Apr 5, 2026
113 days ago
CVE Severity & Scoring
Spotauditor6 CVEs
50%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (50.0%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25434HIGH SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name | Feb 20, 2026 | 7.5 | 26 | NO | NO |
CVE-2019-25666MEDIUM SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an ov | Apr 5, 2026 | 6.2 | 24 | NO | NO |
CVE-2019-25336HIGH SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious paylo | Feb 12, 2026 | 7.8 | 24 | NO | NO |
CVE-2019-25340HIGH SpotAuditor 5.3.2 contains a denial of service vulnerability in its Base64 decryption feature that allows attackers to crash the application by supplying an oversized buffer. Attac | Feb 12, 2026 | 7.5 | 22 | NO | NO |
CVE-2021-27722MEDIUM An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data into the "Key" or "Name" field while registering. | Nov 2, 2021 | 5.5 | 22 | NO | NO |
CVE-2019-25596MEDIUM SpotAuditor 5.2.6 contains a denial of service vulnerability in the registration dialog that allows local attackers to crash the application by supplying an excessively long string | Mar 22, 2026 | 6.2 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Spotauditor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.3.5 | 1 | 5.5 | 0.7% | 0 | 0 |
| 5.3.2 | 2 | 7.7 | 0.3% | 0 | 0 |
| 5.2.6 | 1 | 6.2 | 0.2% | 0 | 0 |