CVE Tools

Gonitro

21 CVEs tracked since 2017. Since Feb 2017, none of them reached CISA KEV.

Gonitro CVEs per month

Feb 2017 to Jan 2021. Point at a month, or focus the strip and use the arrow keys.
Gonitro CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0230
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-1060
2019-11null or fewer
2019-1230
2020-01null or fewer
2020-02null or fewer
2020-0320
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-0950
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-0120

Products

The products that kept showing up in Gonitro's monthly top three, with their CVEs summed over those months.

  1. Nitro Pro93 months
  2. Nitropdf72 months
  3. Nitro Pdf Pro31 month
  4. Nitro Free Pdf Reader21 month
  5. Nitro Reader21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Gonitro.

  1. CVE-2025-69624Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and ...7.5
  2. CVE-2025-69627Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDoc(). During execution, an internal XID object is allocated...8.4
  3. CVE-2025-66769A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) via a crafted XFA packet.7.5
  4. CVE-2025-67825An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information from a non-verified PDF field rather than from the verified certificate subj...5.5
  5. CVE-2021-21797An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a reference to a timeout object to be stored in two differe...7.8
  6. CVE-2021-21796An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destro...7.8
  7. CVE-2021-21798An exploitable return of stack variable address vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause a stack variable to go out of scope, r...7.8
  8. CVE-2018-18689The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability ex...5.3
  9. CVE-2018-18688The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, an Incremental Saving vulnerability e...5.3
  10. CVE-2020-6113An exploitable vulnerability exists in the object stream parsing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when updating its cross-reference table. When processing an object s...7.8
  11. CVE-2020-6112An exploitable code execution vulnerability exists in the JPEG2000 Stripe Decoding functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242 when decoding sub-samples. While initializing tile...7.8
  12. CVE-2020-6115An exploitable vulnerability exists in the cross-reference table repairing functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. While searching for an object identifier in a malformed d...7.8
  13. CVE-2020-6116An arbitrary code execution vulnerability exists in the rendering functionality of Nitro Software, Inc.’s Nitro Pro 13.13.2.242. When drawing the contents of a page using colors from an indexed c...7.8
  14. CVE-2020-6146An exploitable code execution vulnerability exists in the rendering functionality of Nitro Pro 13.13.2.242 and 13.16.2.300. When drawing the contents of a page and selecting the stroke color from a...8.8
  15. CVE-2020-6093An exploitable information disclosure vulnerability exists in the way Nitro Pro 13.9.1.155 does XML error handling. A specially crafted PDF document can cause uninitialized memory access resulting ...5.5

The record

Peak rank
#72 in Oct 2019
Busiest month shown
Oct 2019, 6 CVEs
Months with a KEV entry
0 since Feb 2017
Monthly snapshots
6 since 2017
Gonitro's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store