Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 300 respecto a la semana anterior
Críticas / altas1348▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.12%—Standard NotesAIEvernoteAIGoogle KeepAI7/9/20269/9/2026
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and…
AplazadaAlta (7.8)1.4%—Evernote MCP ServerAI6/11/202517/6/2026
evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of evernote-mcp-server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AplazadaAlta (7.1)0.44%—Tgw365 Evernote SyncAI16/12/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tgw365 Evernote Sync evernote-sync allows Reflected XSS.This issue affects Evernote Sync: from n/a through <= 3.0.0.
ModificadaCrítica (9.8)1.7%—Evernote9/1/20249/7/2026
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
ModificadaAlta (8.8)3.4%—Evernote24/6/202117/6/2026
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
ModificadaMedia (5.4)0.52%—Evernote Yinxiang Biji2/3/202017/6/2026
The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote users; however, it is a vulnerability in YXBJ, not a vulnerability in Evernote.
ModificadaAlta (7.1)0.48%—Evernote31/1/202016/6/2026
Evernote prior to 5.5.1 has insecure password change
ModificadaMedia (4.6)0.55%—Evernote31/1/202016/6/2026
Evernote before 5.5.1 has insecure PIN storage
ModificadaAlta (7.8)1.6%—Evernote30/9/201917/6/2026
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.
ModificadaMedia (6.1)1.1%—Evernote WEB Clipper18/6/201917/6/2026
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in the context of any loaded 3rd-party IFrame.
ModificadaAlta (7.8)1.3%—Evernote31/5/201917/6/2026
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file.
ModificadaMedia (6.1)1.9%—Evernote13/5/201917/6/2026
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
ModificadaMedia (6.1)0.65%—Evernote22/12/201817/6/2026
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.
ModificadaAlta (7.5)1.4%—Evernote11/12/201817/6/2026
In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.
ModificadaAlta (7.8)1.5%—Evernote22/5/201717/6/2026
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.