Записи notepad-plus-plus
21 опубликованных записей вендора notepad-plus-plus.
Профиль для исследователя
- Попали в KEV
- 1 · 4,8 %
- С эксплойтом
- 1 · 4,8 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 38,1 %
- Медиана: публикация → KEV
- 10 дн.
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-427 Uncontrolled Search Path Element3
- CWE-787 Out-of-bounds Write3
- CWE-426 Untrusted Search Path2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2025-15556Готовый эксплойт | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verificationnotepad-plus-plus · notepad\+\+ · CWE-494 | Высокая7,7 | KEV | 1,7 % | 2 февр. 2026 г. |
34Наблюдать | CVE-2019-16294Proof of concept | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a craftescintilla · scintilla · CWE-787 | Высокая7,8 | — | 9,8 % | 14 сент. 2019 г. |
31Наблюдать | CVE-2017-8803Эксплойта нет | Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a mh-nexus · hex editor · CWE-119 | Высокая7,8 | — | 1,6 % | 5 июл. 2017 г. |
31Наблюдать | CVE-2022-32168Эксплойта нет | notepad-plus-plus - DLL Hijackingnotepad-plus-plus · notepad\+\+ · CWE-427 | Высокая7,8 | — | 0,8 % | 28 сент. 2022 г. |
31Наблюдать | CVE-2026-48778Proof of concept | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreternotepad-plus-plus · notepad\+\+ · CWE-78 | Высокая7,8 | — | 0,6 % | 26 июн. 2026 г. |
31Наблюдать | CVE-2023-47452Эксплойта нет | An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the notepad-plus-plus · notepad\+\+ · CWE-427 | Высокая7,8 | — | 0,5 % | 30 нояб. 2023 г. |
31Наблюдать | CVE-2023-40031Proof of concept | Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertnotepad-plus-plus · notepad\+\+ · CWE-120 | Высокая7,8 | — | 0,5 % | 25 авг. 2023 г. |
31Наблюдать | CVE-2023-6401Proof of concept | NotePad++ dbghelp.exe uncontrolled search pathnotepad-plus-plus · notepad\+\+ · CWE-427 | Высокая7,8 | — | 0,3 % | 30 нояб. 2023 г. |
31Наблюдать | CVE-2026-48800Proof of concept | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injectionnotepad-plus-plus · notepad\+\+ · CWE-78 | Высокая7,8 | — | 0,2 % | 26 июн. 2026 г. |
31Наблюдать | CVE-2026-52884Эксплойта нет | Notepad++: CVE-2026-48800 Bypassnotepad-plus-plus · notepad\+\+ · CWE-42 | Высокая7,8 | — | 0,2 % | 26 июн. 2026 г. |
31Наблюдать | CVE-2026-5525Эксплойта нет | Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoSnotepad-plus-plus · notepad\+\+ · CWE-121 | Высокая7,8 | — | 0,2 % | 10 апр. 2026 г. |
30Наблюдать | CVE-2026-46710Эксплойта нет | Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Pathnotepad-plus-plus · notepad\+\+ · CWE-426 | Высокая7,5 | — | 0,2 % | 26 июн. 2026 г. |
30Наблюдать | CVE-2026-52885Proof of concept | Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memorynotepad-plus-plus · notepad\+\+ · CWE-367 | Высокая7,5 | — | 0,1 % | 26 июн. 2026 г. |
29Наблюдать | CVE-2026-25926Эксплойта нет | Notepad++ has an Untrusted Search Pathnotepad-plus-plus · notepad\+\+ · CWE-426 | Высокая7,3 | — | 0,2 % | 18 февр. 2026 г. |
26Наблюдать | CVE-2022-31901Proof of concept | Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craftnotepad-plus-plus · notepad\+\+ · CWE-787 | Средняя6,5 | — | 1,3 % | 19 янв. 2023 г. |
22Наблюдать | CVE-2022-31902Proof of concept | Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().notepad-plus-plus · notepad\+\+ · CWE-787 | Средняя5,5 | — | 0,5 % | 31 янв. 2023 г. |
22Наблюдать | CVE-2023-40164Эксплойта нет | Notepad++ global buffer read overflow in nsCodingStateMachine::NextStatenotepad-plus-plus · notepad\+\+ · CWE-120 | Средняя5,5 | — | 0,5 % | 25 авг. 2023 г. |
22Наблюдать | CVE-2023-40166Эксплойта нет | Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBeginingnotepad-plus-plus · notepad\+\+ · CWE-120 | Средняя5,5 | — | 0,4 % | 25 авг. 2023 г. |
22Наблюдать | CVE-2023-40036Эксплойта нет | Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneCharnotepad-plus-plus · notepad\+\+ · CWE-120 | Средняя5,5 | — | 0,4 % | 25 авг. 2023 г. |
20Наблюдать | CVE-2026-48770Proof of concept | Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crashnotepad-plus-plus · notepad\+\+ · CWE-125 | Средняя5,0 | — | 0,1 % | 26 июн. 2026 г. |
18Наблюдать | CVE-2026-6539Эксплойта нет | Notepad++ 8.9.3 Format String Injection via nativeLang.xmlnotepad-plus-plus · notepad\+\+ · CWE-134 | Средняя4,6 | — | 0,2 % | 30 апр. 2026 г. |
- CVE-2025-1555661На этой неделе
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
ВысокаяCVSS 7,7KEVГотовый эксплойтEPSS 2 %notepad-plus-plus · notepad\+\+2 февр. 2026 г.
- CVE-2019-1629434Наблюдать
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafte
ВысокаяCVSS 7,8Proof of conceptEPSS 10 %scintilla · scintilla14 сент. 2019 г.
- CVE-2017-880331Наблюдать
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %mh-nexus · hex editor5 июл. 2017 г.
- CVE-2022-3216831Наблюдать
notepad-plus-plus - DLL Hijacking
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %notepad-plus-plus · notepad\+\+28 сент. 2022 г.
- CVE-2026-4877831Наблюдать
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %notepad-plus-plus · notepad\+\+26 июн. 2026 г.
- CVE-2023-4745231Наблюдать
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %notepad-plus-plus · notepad\+\+30 нояб. 2023 г.
- CVE-2023-4003131Наблюдать
Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %notepad-plus-plus · notepad\+\+25 авг. 2023 г.
- CVE-2023-640131Наблюдать
NotePad++ dbghelp.exe uncontrolled search path
ВысокаяCVSS 7,8Proof of conceptEPSS 0 %notepad-plus-plus · notepad\+\+30 нояб. 2023 г.
- CVE-2026-4880031Наблюдать
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
ВысокаяCVSS 7,8Proof of conceptEPSS 0 %notepad-plus-plus · notepad\+\+26 июн. 2026 г.
- CVE-2026-5288431Наблюдать
Notepad++: CVE-2026-48800 Bypass
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+26 июн. 2026 г.
- CVE-2026-552531Наблюдать
Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+10 апр. 2026 г.
- CVE-2026-4671030Наблюдать
Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+26 июн. 2026 г.
- CVE-2026-5288530Наблюдать
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
ВысокаяCVSS 7,5Proof of conceptEPSS 0 %notepad-plus-plus · notepad\+\+26 июн. 2026 г.
- CVE-2026-2592629Наблюдать
Notepad++ has an Untrusted Search Path
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+18 февр. 2026 г.
- CVE-2022-3190126Наблюдать
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craft
СредняяCVSS 6,5Proof of conceptEPSS 1 %notepad-plus-plus · notepad\+\+19 янв. 2023 г.
- CVE-2022-3190222Наблюдать
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
СредняяCVSS 5,5Proof of conceptEPSS 1 %notepad-plus-plus · notepad\+\+31 янв. 2023 г.
- CVE-2023-4016422Наблюдать
Notepad++ global buffer read overflow in nsCodingStateMachine::NextState
СредняяCVSS 5,5Эксплойта нетEPSS 1 %notepad-plus-plus · notepad\+\+25 авг. 2023 г.
- CVE-2023-4016622Наблюдать
Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining
СредняяCVSS 5,5Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+25 авг. 2023 г.
- CVE-2023-4003622Наблюдать
Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar
СредняяCVSS 5,5Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+25 авг. 2023 г.
- CVE-2026-4877020Наблюдать
Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
СредняяCVSS 5,0Proof of conceptEPSS 0 %notepad-plus-plus · notepad\+\+26 июн. 2026 г.
- CVE-2026-653918Наблюдать
Notepad++ 8.9.3 Format String Injection via nativeLang.xml
СредняяCVSS 4,6Эксплойта нетEPSS 0 %notepad-plus-plus · notepad\+\+30 апр. 2026 г.