Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.3)0.18%—Flos-freeware Notepad222/3/202617/6/2026
A security flaw has been discovered in Flos Freeware Notepad2 4.2.25. This affects an unknown function in the library PROPSYS.dll. Performing a manipulation results in uncontrolled search path. The attack is only possible with local access. The attack is considered to have high complexity. The exploitability is…
AnalizadaAlta (7.3)0.21%—Notepad-plus-plus Notepad++19/2/202617/6/2026
Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory.…
AplazadaAlta (7.3)0.17%—Flos Freeware Notepad2AI16/2/202617/6/2026
A security flaw has been discovered in Flos Freeware Notepad2 4.2.22/4.2.23/4.2.24/4.2.25. Affected is an unknown function in the library Msimg32.dll. Performing a manipulation results in uncontrolled search path. Attacking locally is a requirement. The attack's complexity is rated as high. The exploitability is told…
AnalizadaAlta (7.8)13%—Microsoft Windows Notepad10/2/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.7)1.8%⚠ Explotación activaNotepad-plus-plus Notepad++3/2/202617/6/2026
Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an…
AplazadaAlta (8.4)0.38%—Notepad++AI26/9/202517/6/2026
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users.
AplazadaMedia (4.3)0.16%—Stephanieleary Dashboard NotepadAI22/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Dashboard Notepad dashboard-notepad allows Cross Site Request Forgery.This issue affects Dashboard Notepad: from n/a through <= 1.42.
AplazadaAlta (7.3)0.66%—Notepad++AI23/6/202517/6/2026
Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or…
AplazadaCrítica (9.4)0.18%—NotepadnextAI23/6/202517/6/2026
Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C. This issue affects NotepadNext: through v0.11.
AplazadaMedia (5.1)0.18%—NotepadnextAI23/6/202517/6/2026
Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects NotepadNext: through v0.11. The singlevar() in lparser.c lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a…
AplazadaAlta (7.1)0.15%—Swedish BOY Dashboard NotepadsAI17/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.This issue affects Dashboard Notepads: from n/a through <= 1.2.1.
ModificadaMedia (5.5)0.21%—Rizonesoft Notepad32/2/202417/6/2026
A vulnerability, which was classified as problematic, was found in Rizone Soft Notepad3 1.0.2.350. Affected is an unknown function of the component Encryption Passphrase Handler. The manipulation leads to denial of service. Attacking locally is a requirement. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.8)0.53%—Notepad-plus-plus Notepad++30/11/202317/6/2026
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.
ModificadaAlta (7.8)0.33%—Notepad-plus-plus Notepad++30/11/202317/6/2026
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE:…
ModificadaMedia (5.5)0.41%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of…
ModificadaMedia (5.5)0.50%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no…
ModificadaMedia (5.5)0.38%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of…
ModificadaAlta (7.8)0.52%—Notepad-plus-plus Notepad++25/8/202317/6/2026
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.
ModificadaMedia (5.5)0.27%—Notepad-- Project Notepad--18/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of the component Directory Comparison Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The associated identifier of this vulnerability is VDB-221475.
ModificadaMedia (5.5)0.52%—Notepad-plus-plus Notepad++1/2/20239/7/2026
Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().
ModificadaMedia (6.5)1.3%—Notepad-plus-plus Notepad++19/1/202317/6/2026
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.
ModificadaAlta (7.8)0.75%—Notepad-plus-plus Notepad++28/9/202217/6/2026
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
ModificadaAlta (7.8)9.8%—Notepad-plus-plus Notepad++Scintilla14/9/201917/6/2026
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
ModificadaAlta (10)11%—DON HO Notepad++2/1/201517/6/2026
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file. NOTE: this issue was originally incorrectly mapped to CVE-2014-1004; see CVE-2014-1004 for more information.
ModificadaAlta (7.5)1.8%—Notepad++1/8/200816/6/2026
The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.