Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-48778
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by …
Notepad\+\+
8.9.6.1+
HIGH 7.8
CVE-2026-48800
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xm…
Notepad\+\+
8.9.6.1+
HIGH 7.8
CVE-2026-52884
Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a…
Notepad\+\+
Patch available
MEDIUM 6.3
CVE-2026-52885
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment …
Notepad\+\+
8.9.6.4+
MEDIUM 5.0
CVE-2026-48770
Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malforme…
Notepad\+\+
8.9.6.1+
HIGH 7.8
CVE-2026-46710
Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the …
Notepad\+\+
8.9.6+
HIGH 7.8
CVE-2026-5525
A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a direc…
Notepad\+\+
Patch available
HIGH 7.3
CVE-2026-25926
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launchin…
Notepad\+\+
8.9.2+
HIGH 7.5
CVE-2025-15556 KEV
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update meta…
Notepad\+\+
8.8.9+
HIGH 7.8
CVE-2023-47452
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current w…
Notepad\+\+
No fix yet
HIGH 7.8
CVE-2023-6401
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file db…
Notepad\+\+
after 8.1
MEDIUM 5.5
CVE-2023-40164
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachi…
Notepad\+\+
after 8.5.6
MEDIUM 5.5
CVE-2023-40166
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectL…
Notepad\+\+
after 8.5.6
HIGH 7.8
CVE-2023-40031
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::conve…
Notepad\+\+
after 8.5.6
MEDIUM 5.5
CVE-2023-40036
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAn…
Notepad\+\+
after 8.5.6
MEDIUM 5.5
CVE-2022-31902
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
Notepad\+\+
after 8.4.3
MEDIUM 6.5
CVE-2022-31901
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.
Notepad\+\+
after 8.4.3
HIGH 7.8
CVE-2022-32168
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll a…
Notepad\+\+
8.4.5+
HIGH 7.8
CVE-2019-16294EPSS 10%
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml fil…
Notepad\+\+
7.7+