notepad-plus-plus kayıtları
notepad-plus-plus üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %4,8
- Silahlaştırılmış
- 1 · %4,8
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %38,1
- Yayından KEV’e ortanca
- 10 gün
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-427 Uncontrolled Search Path Element3
- CWE-787 Out-of-bounds Write3
- CWE-426 Untrusted Search Path2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2025-15556Silahlaştırılmış | Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verificationnotepad-plus-plus · notepad\+\+ · CWE-494 | Yüksek7,7 | KEV | %1,7 | 2 Şub 2026 |
34İzleyin | CVE-2019-16294Kavram kanıtı | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a craftescintilla · scintilla · CWE-787 | Yüksek7,8 | — | %9,8 | 14 Eyl 2019 |
31İzleyin | CVE-2017-8803İstismar yok | Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a mh-nexus · hex editor · CWE-119 | Yüksek7,8 | — | %1,6 | 5 Tem 2017 |
31İzleyin | CVE-2022-32168İstismar yok | notepad-plus-plus - DLL Hijackingnotepad-plus-plus · notepad\+\+ · CWE-427 | Yüksek7,8 | — | %0,8 | 28 Eyl 2022 |
31İzleyin | CVE-2026-48778Kavram kanıtı | Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreternotepad-plus-plus · notepad\+\+ · CWE-78 | Yüksek7,8 | — | %0,6 | 26 Haz 2026 |
31İzleyin | CVE-2023-47452İstismar yok | An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the notepad-plus-plus · notepad\+\+ · CWE-427 | Yüksek7,8 | — | %0,5 | 30 Kas 2023 |
31İzleyin | CVE-2023-40031Kavram kanıtı | Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertnotepad-plus-plus · notepad\+\+ · CWE-120 | Yüksek7,8 | — | %0,5 | 25 Ağu 2023 |
31İzleyin | CVE-2023-6401Kavram kanıtı | NotePad++ dbghelp.exe uncontrolled search pathnotepad-plus-plus · notepad\+\+ · CWE-427 | Yüksek7,8 | — | %0,3 | 30 Kas 2023 |
31İzleyin | CVE-2026-48800Kavram kanıtı | Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injectionnotepad-plus-plus · notepad\+\+ · CWE-78 | Yüksek7,8 | — | %0,2 | 26 Haz 2026 |
31İzleyin | CVE-2026-52884İstismar yok | Notepad++: CVE-2026-48800 Bypassnotepad-plus-plus · notepad\+\+ · CWE-42 | Yüksek7,8 | — | %0,2 | 26 Haz 2026 |
31İzleyin | CVE-2026-5525İstismar yok | Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoSnotepad-plus-plus · notepad\+\+ · CWE-121 | Yüksek7,8 | — | %0,2 | 10 Nis 2026 |
30İzleyin | CVE-2026-46710İstismar yok | Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Pathnotepad-plus-plus · notepad\+\+ · CWE-426 | Yüksek7,5 | — | %0,2 | 26 Haz 2026 |
30İzleyin | CVE-2026-52885Kavram kanıtı | Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memorynotepad-plus-plus · notepad\+\+ · CWE-367 | Yüksek7,5 | — | %0,1 | 26 Haz 2026 |
29İzleyin | CVE-2026-25926İstismar yok | Notepad++ has an Untrusted Search Pathnotepad-plus-plus · notepad\+\+ · CWE-426 | Yüksek7,3 | — | %0,2 | 18 Şub 2026 |
26İzleyin | CVE-2022-31901Kavram kanıtı | Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craftnotepad-plus-plus · notepad\+\+ · CWE-787 | Orta6,5 | — | %1,3 | 19 Oca 2023 |
22İzleyin | CVE-2022-31902Kavram kanıtı | Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().notepad-plus-plus · notepad\+\+ · CWE-787 | Orta5,5 | — | %0,5 | 31 Oca 2023 |
22İzleyin | CVE-2023-40164İstismar yok | Notepad++ global buffer read overflow in nsCodingStateMachine::NextStatenotepad-plus-plus · notepad\+\+ · CWE-120 | Orta5,5 | — | %0,5 | 25 Ağu 2023 |
22İzleyin | CVE-2023-40166İstismar yok | Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBeginingnotepad-plus-plus · notepad\+\+ · CWE-120 | Orta5,5 | — | %0,4 | 25 Ağu 2023 |
22İzleyin | CVE-2023-40036İstismar yok | Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneCharnotepad-plus-plus · notepad\+\+ · CWE-120 | Orta5,5 | — | %0,4 | 25 Ağu 2023 |
20İzleyin | CVE-2026-48770Kavram kanıtı | Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crashnotepad-plus-plus · notepad\+\+ · CWE-125 | Orta5,0 | — | %0,1 | 26 Haz 2026 |
18İzleyin | CVE-2026-6539İstismar yok | Notepad++ 8.9.3 Format String Injection via nativeLang.xmlnotepad-plus-plus · notepad\+\+ · CWE-134 | Orta4,6 | — | %0,2 | 30 Nis 2026 |
- CVE-2025-1555661Bu hafta
Notepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity Verification
YüksekCVSS 7,7KEVSilahlaştırılmışEPSS %2notepad-plus-plus · notepad\+\+2 Şub 2026
- CVE-2019-1629434İzleyin
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafte
YüksekCVSS 7,8Kavram kanıtıEPSS %10scintilla · scintilla14 Eyl 2019
- CVE-2017-880331İzleyin
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a
YüksekCVSS 7,8İstismar yokEPSS %2mh-nexus · hex editor5 Tem 2017
- CVE-2022-3216831İzleyin
notepad-plus-plus - DLL Hijacking
YüksekCVSS 7,8İstismar yokEPSS %1notepad-plus-plus · notepad\+\+28 Eyl 2022
- CVE-2026-4877831İzleyin
Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter
YüksekCVSS 7,8Kavram kanıtıEPSS %1notepad-plus-plus · notepad\+\+26 Haz 2026
- CVE-2023-4745231İzleyin
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the
YüksekCVSS 7,8İstismar yokEPSS %1notepad-plus-plus · notepad\+\+30 Kas 2023
- CVE-2023-4003131İzleyin
Notepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convert
YüksekCVSS 7,8Kavram kanıtıEPSS %1notepad-plus-plus · notepad\+\+25 Ağu 2023
- CVE-2023-640131İzleyin
NotePad++ dbghelp.exe uncontrolled search path
YüksekCVSS 7,8Kavram kanıtıEPSS %0notepad-plus-plus · notepad\+\+30 Kas 2023
- CVE-2026-4880031İzleyin
Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection
YüksekCVSS 7,8Kavram kanıtıEPSS %0notepad-plus-plus · notepad\+\+26 Haz 2026
- CVE-2026-5288431İzleyin
Notepad++: CVE-2026-48800 Bypass
YüksekCVSS 7,8İstismar yokEPSS %0notepad-plus-plus · notepad\+\+26 Haz 2026
- CVE-2026-552531İzleyin
Stack-Based Buffer Overflow in Notepad++ File Drop Handler leads to DoS
YüksekCVSS 7,8İstismar yokEPSS %0notepad-plus-plus · notepad\+\+10 Nis 2026
- CVE-2026-4671030İzleyin
Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path
YüksekCVSS 7,5İstismar yokEPSS %0notepad-plus-plus · notepad\+\+26 Haz 2026
- CVE-2026-5288530İzleyin
Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory
YüksekCVSS 7,5Kavram kanıtıEPSS %0notepad-plus-plus · notepad\+\+26 Haz 2026
- CVE-2026-2592629İzleyin
Notepad++ has an Untrusted Search Path
YüksekCVSS 7,3İstismar yokEPSS %0notepad-plus-plus · notepad\+\+18 Şub 2026
- CVE-2022-3190126İzleyin
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two craft
OrtaCVSS 6,5Kavram kanıtıEPSS %1notepad-plus-plus · notepad\+\+19 Oca 2023
- CVE-2022-3190222İzleyin
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
OrtaCVSS 5,5Kavram kanıtıEPSS %1notepad-plus-plus · notepad\+\+31 Oca 2023
- CVE-2023-4016422İzleyin
Notepad++ global buffer read overflow in nsCodingStateMachine::NextState
OrtaCVSS 5,5İstismar yokEPSS %1notepad-plus-plus · notepad\+\+25 Ağu 2023
- CVE-2023-4016622İzleyin
Notepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining
OrtaCVSS 5,5İstismar yokEPSS %0notepad-plus-plus · notepad\+\+25 Ağu 2023
- CVE-2023-4003622İzleyin
Notepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneChar
OrtaCVSS 5,5İstismar yokEPSS %0notepad-plus-plus · notepad\+\+25 Ağu 2023
- CVE-2026-4877020İzleyin
Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash
OrtaCVSS 5,0Kavram kanıtıEPSS %0notepad-plus-plus · notepad\+\+26 Haz 2026
- CVE-2026-653918İzleyin
Notepad++ 8.9.3 Format String Injection via nativeLang.xml
OrtaCVSS 4,6İstismar yokEPSS %0notepad-plus-plus · notepad\+\+30 Nis 2026