Skip to content
Noroxi

notepad-plus-plus records

21 published records for vendor notepad-plus-plus.

All records

21 records
  • CVE-2025-15556
    61This week

    Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification

    HighCVSS 7.7KEVWeaponizedEPSS 2%

    notepad-plus-plus · notepad\+\+Feb 2, 2026

  • SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafte

    HighCVSS 7.8Proof of conceptEPSS 10%

    scintilla · scintillaSep 14, 2019

  • CVE-2017-8803
    31Monitor

    Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a

    HighCVSS 7.8No exploitEPSS 2%

    mh-nexus · hex editorJul 5, 2017

  • notepad-plus-plus - DLL Hijacking

    HighCVSS 7.8No exploitEPSS 1%

    notepad-plus-plus · notepad\+\+Sep 28, 2022

  • Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter

    HighCVSS 7.8Proof of conceptEPSS 1%

    notepad-plus-plus · notepad\+\+Jun 26, 2026

  • An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the

    HighCVSS 7.8No exploitEPSS 1%

    notepad-plus-plus · notepad\+\+Nov 30, 2023

  • Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert

    HighCVSS 7.8Proof of conceptEPSS 1%

    notepad-plus-plus · notepad\+\+Aug 25, 2023

  • CVE-2023-6401
    31Monitor

    NotePad++ dbghelp.exe uncontrolled search path

    HighCVSS 7.8Proof of conceptEPSS 0%

    notepad-plus-plus · notepad\+\+Nov 30, 2023

  • Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection

    HighCVSS 7.8Proof of conceptEPSS 0%

    notepad-plus-plus · notepad\+\+Jun 26, 2026

  • Notepad++: CVE-2026-48800 Bypass

    HighCVSS 7.8No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Jun 26, 2026

  • CVE-2026-5525
    31Monitor

    Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS

    HighCVSS 7.8No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Apr 10, 2026

  • Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path

    HighCVSS 7.5No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Jun 26, 2026

  • Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory

    HighCVSS 7.5Proof of conceptEPSS 0%

    notepad-plus-plus · notepad\+\+Jun 26, 2026

  • Notepad++ has an Untrusted Search Path

    HighCVSS 7.3No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Feb 18, 2026

  • Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craft

    MediumCVSS 6.5Proof of conceptEPSS 1%

    notepad-plus-plus · notepad\+\+Jan 19, 2023

  • Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().

    MediumCVSS 5.5Proof of conceptEPSS 1%

    notepad-plus-plus · notepad\+\+Jan 31, 2023

  • Notepad++ global buffer read overflow in nsCodingStateMachine::NextState

    MediumCVSS 5.5No exploitEPSS 1%

    notepad-plus-plus · notepad\+\+Aug 25, 2023

  • Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining

    MediumCVSS 5.5No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Aug 25, 2023

  • Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar

    MediumCVSS 5.5No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Aug 25, 2023

  • Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash

    MediumCVSS 5.0Proof of conceptEPSS 0%

    notepad-plus-plus · notepad\+\+Jun 26, 2026

  • CVE-2026-6539
    18Monitor

    Notepad++ 8.9.3 Format String Injection via nativeLang.xml

    MediumCVSS 4.6No exploitEPSS 0%

    notepad-plus-plus · notepad\+\+Apr 30, 2026