Vulnerabilities
Summary — last 7 days
New vulnerabilities2,751▼ 38 vs. last week
Critical / high1,262▼ 270 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 209 vs. last week
33 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (5.5) | 0.38% | — | Notepad-plus-plus Notepad++ | 8/25/2023 | 6/17/2026 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of… | |
| Modified | High (7.8) | 0.52% | 💥 PoC | Notepad-plus-plus Notepad++ | 8/25/2023 | 6/17/2026 | Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++. | |
| Modified | Medium (5.5) | 0.52% | 💥 PoC | Notepad-plus-plus Notepad++ | 2/1/2023 | 7/9/2026 | Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add(). | |
| Modified | Medium (6.5) | 1.3% | 💥 PoC | Notepad-plus-plus Notepad++ | 1/19/2023 | 6/17/2026 | Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files. | |
| Modified | High (7.8) | 0.75% | — | Notepad-plus-plus Notepad++ | 9/28/2022 | 6/17/2026 | Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++. | |
| Modified | Critical (9.8) | 2.0% | — | Baomidou Mybatis-plus | 3/22/2022 | 6/17/2026 | MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior. | |
| Modified | High (7.8) | 9.8% | 💥 Exploit | Notepad-plus-plus Notepad++Scintilla | 9/14/2019 | 6/17/2026 | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file. | |
| Modified | Medium (4.6) | 0.33% | — | Splus S-plusAI | 12/31/2003 | 6/16/2026 | S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6)… |