Voidtools maintains Everything, a file-search and indexing utility for Windows, with a small vulnerability surface centered on HTTP-header handling and regular-expression parsing. The observed weakness classes reflect the application's text-processing and web-integration components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Voidtools over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20784MEDIUM HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website t | Jul 14, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-27704MEDIUM Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS). | Apr 12, 2023 | 5.5 | 20 | NO | NO |
CVE-2020-24567HIGH voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file in the installation directory. NOTE: this is only relevant | Aug 21, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Voidtools.
Media articles that mention a CVE ID that affects a product developed by Voidtools — matched by CVE ID, not by vendor name.