CVE-2020-37198: Digitalvolcano Software Duplicate Cleaner Pro

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Duplicate Cleaner Pro 4.1.3 contains a denial of service vulnerability that allows attackers to crash the application by injecting an oversized buffer into the license key field. Attackers can generate a 6000-byte payload and paste it into the license activation field to trigger an application crash.

Affected products

Published 2026-02-11. Last modified 2026-06-17.