CVE-2025-12489
- EPSS 0.08%
- Veröffentlicht 06.11.2025 20:11:32
- Zuletzt bearbeitet 12.11.2025 16:20:22
evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of evernote-mcp-server. An attacker must first obtain the ability to exec...
CVE-2023-50643
- EPSS 26.93%
- Veröffentlicht 09.01.2024 01:15:38
- Zuletzt bearbeitet 03.06.2025 15:15:46
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
CVE-2020-17759
- EPSS 0.47%
- Veröffentlicht 24.06.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:20
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
CVE-2013-5116
- EPSS 0.09%
- Veröffentlicht 31.01.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 01:57:02
Evernote prior to 5.5.1 has insecure password change
CVE-2013-5112
- EPSS 0.1%
- Veröffentlicht 31.01.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 01:57:02
Evernote before 5.5.1 has insecure PIN storage
CVE-2019-17051
- EPSS 0.39%
- Veröffentlicht 30.09.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 04:31:36
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.
CVE-2019-10038
- EPSS 2.3%
- Veröffentlicht 31.05.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:15
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Calculator file.
CVE-2018-18524
- EPSS 0.58%
- Veröffentlicht 13.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:05
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's ...
CVE-2018-20351
- EPSS 0.3%
- Veröffentlicht 22.12.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:17
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.
CVE-2018-20058
- EPSS 0.43%
- Veröffentlicht 11.12.2018 09:29:00
- Zuletzt bearbeitet 21.11.2024 04:00:49
In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.