Vulnerabilidades em notepad-plus-plus

25 resultados
Análise Vexday

Notepad++ apresenta 14 vulnerabilidades catalogadas, com 1 sob exploração ativa e 6 divulgadas nos últimos 90 dias, indicando ritmo recente de descobertas. A ausência de críticas (CVSS alto) e a dominância de CWE-120 (buffer overflow) sugerem risco moderado, concentrado em falhas de validação de entrada que exigem monitoramento contínuo.

CVE-2025-15556HIGHNotepad++ < 8.8.9 WinGUp Updater Lacks Update Integrity VerificationEPSS 1.7%KEVCVE-2022-32168HIGHnotepad-plus-plus - DLL HijackingEPSS 0.7%CVE-2025-49144HIGHNotepad++ Privilege Escalation in Installer via Uncontrolled Executable Search PathEPSS 0.6%CVE-2026-48778HIGHNotepad++: Arbitrary Code Execution via config.xml commandLineInterpreterEPSS 0.6%CVE-2026-57233HIGHNotepad++: Path Traversal (Zip Slip) in WinGup Plugin ExtractionEPSS 0.5%CVE-2023-40031HIGHNotepad++ vulnerable to heap buffer write overflow in Utf8_16_Read::convertEPSS 0.5%CVE-2023-40164MEDIUMNotepad++ global buffer read overflow in nsCodingStateMachine::NextStateEPSS 0.5%CVE-2023-40166MEDIUMNotepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining EPSS 0.4%CVE-2023-40036MEDIUMNotepad++ global buffer read overflow in CharDistributionAnalysis::HandleOneCharEPSS 0.4%CVE-2026-25926HIGHNotepad++ has an Untrusted Search PathEPSS 0.3%CVE-2026-52886MEDIUMNotepad++: session.xml backupFilePath starts_with BypassEPSS 0.2%CVE-2026-48800HIGHNotepad++: Arbitrary Code Execution via shortcuts.xml UserCommand InjectionEPSS 0.2%CVE-2026-52884HIGHNotepad++: CVE-2026-48800 BypassEPSS 0.2%CVE-2026-54758HIGHNotepad++: Stack Buffer Overflow in expandNppEnvironmentStrsEPSS 0.2%CVE-2026-46710HIGHNotepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search PathEPSS 0.2%CVE-2026-48770MEDIUMNotepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crashEPSS 0.1%CVE-2026-71858MEDIUMNotepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command ExecutionEPSS 0.1%CVE-2026-73250MEDIUMNotepad++: Install-time PowerShell command injection through installation pathEPSS 0.1%CVE-2026-52885HIGHNotepad++ TOCTOU: HMAC Checks Disk, Executes from MemoryEPSS 0.1%CVE-2026-85288MEDIUMNotepad++: Shortcuts.xml macro HMAC bypass still reachable via the "Run a Macro Multiple Times" dialogEPSS