Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Daniel Cifuentes

#21491of 56,330
12.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-52972
7.8
2026-06-26
Notepad++ · Notepad++ · CVE-2026-46710
**Name of the Vulnerable Software and Affected Versions** Notepad++ versions 8.9.4 through 8.9.5 **Description** The installer contains a local privilege escalation issue. During the installation process, the installer invokes `powershell.exe` without specifying an absolute path after setting the working directory to the installation contextMenu directory. An attacker can exploit this by placing a malicious `powershell.exe` file in a user-writable custom installation directory. If a privileged user subsequently runs the installer and selects that specific directory, the malicious executable is launched with the elevated privileges of the installer. **Recommendations** Update to version 8.9.6.
PT-2026-44374
5.0
2026-05-26
Notepad++ · Notepad++ · CVE-2026-48770
**Name of the Vulnerable Software and Affected Versions** Notepad++ versions prior to 8.9.6.1 **Description** Multiple issues exist in the software, including a buffer over-read in the inter-process communication mechanism that can lead to a denial of service. Additionally, remote code execution is possible through configuration file injection because the application passes `commandLineInterpreter` from 'config.xml' and `UserDefinedCommands` from 'shortcuts.xml' directly to the `ShellExecute()` function without validation. **Recommendations** Update to version 8.9.6.1.