Evernote
Evernote: vulnerabilidades y CVE
Evernote tiene 11 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-78325 | Media (6.9) | 0.12% | — | 7 sept 2026 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a… |
| CVE-2023-50643 | Crítica (9.8) | 1.7% | — | 9 ene 2024 | An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components. |
| CVE-2020-17759 | Alta (8.8) | 3.4% | — | 24 jun 2021 | An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941. |
| CVE-2013-5116 | Alta (7.1) | 0.48% | — | 31 ene 2020 | Evernote prior to 5.5.1 has insecure password change |
| CVE-2013-5112 | Media (4.6) | 0.55% | — | 31 ene 2020 | Evernote before 5.5.1 has insecure PIN storage |
| CVE-2019-17051 | Alta (7.8) | 1.6% | — | 30 sept 2019 | Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted… |
| CVE-2019-10038 | Alta (7.8) | 1.3% | — | 31 may 2019 | Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file. |
| CVE-2018-18524 | Media (6.1) | 1.9% | — | 13 may 2019 | Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the… |
| CVE-2018-20351 | Media (6.1) | 0.65% | — | 22 dic 2018 | The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832. |
| CVE-2018-20058 | Alta (7.5) | 1.4% | — | 11 dic 2018 | In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634. |
| CVE-2016-4900 | Alta (7.8) | 1.5% | — | 22 may 2017 | Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory. |