Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-48778 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> tag in config.xml is read by … Notepad\+\+ 8.9.6.1+ Fix from $1,9502026-06-26 HIGH 7.8 CVE-2026-48800 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDefinedCommands> in shortcuts.xm… Notepad\+\+ 8.9.6.1+ Fix from $1,9502026-06-26 HIGH 7.8 CVE-2026-52884 Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a… Notepad\+\+ Patch available Fix from $1,9502026-06-26 MEDIUM 6.3 CVE-2026-52885 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk shortcuts.xml at the moment … Notepad\+\+ 8.9.6.4+ Fix from $1,6002026-06-26 MEDIUM 5.0 CVE-2026-48770 Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malforme… Notepad\+\+ 8.9.6.1+ Fix from $1,6002026-06-26 HIGH 7.8 CVE-2026-46710 Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege escalation vulnerability in the … Notepad\+\+ 8.9.6+ Fix from $1,9502026-06-26 HIGH 7.8 CVE-2026-5525 A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a direc… Notepad\+\+ Patch available Fix from $1,9502026-04-10 HIGH 7.3 CVE-2026-25926 Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launchin… Notepad\+\+ 8.9.2+ Fix from $1,9502026-02-19 HIGH 7.5 CVE-2025-15556 KEV Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update meta… Notepad\+\+ 8.8.9+ Fix from $1,9502026-02-03 HIGH 7.8 CVE-2023-47452 An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current w… Notepad\+\+ No fix yet Fix from $1,9502023-11-30 HIGH 7.8 CVE-2023-6401 A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file db… Notepad\+\+ after 8.1 Fix from $1,9502023-11-30 MEDIUM 5.5 CVE-2023-40164 Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachi… Notepad\+\+ after 8.5.6 Fix from $1,6002023-08-25 MEDIUM 5.5 CVE-2023-40166 Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectL… Notepad\+\+ after 8.5.6 Fix from $1,6002023-08-25 HIGH 7.8 CVE-2023-40031 Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::conve… Notepad\+\+ after 8.5.6 Fix from $1,9502023-08-25 MEDIUM 5.5 CVE-2023-40036 Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAn… Notepad\+\+ after 8.5.6 Fix from $1,6002023-08-25 MEDIUM 5.5 CVE-2022-31902 Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add(). Notepad\+\+ after 8.4.3 Fix from $1,6002023-02-01 MEDIUM 6.5 CVE-2022-31901 Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files. Notepad\+\+ after 8.4.3 Fix from $1,6002023-01-19 HIGH 7.8 CVE-2022-32168 Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll a… Notepad\+\+ 8.4.5+ Fix from $1,9502022-09-28 HIGH 7.8 CVE-2019-16294EPSS 10% SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml fil… Notepad\+\+ 7.7+ Fix from $1,9502019-09-14