CVE-2024-29028
- EPSS 1.05%
- Veröffentlicht 19.04.2024 15:15:50
- Zuletzt bearbeitet 07.07.2025 16:03:50
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthenticated users to enumerate the internal network and receive limited html values in json form. This vul...
CVE-2023-5036
- EPSS 0.29%
- Veröffentlicht 18.09.2023 06:15:08
- Zuletzt bearbeitet 21.11.2024 08:40:56
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
CVE-2023-4698
- EPSS 0.76%
- Veröffentlicht 01.09.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:42
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4697
- EPSS 0.7%
- Veröffentlicht 01.09.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:42
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
CVE-2023-4696
- EPSS 0.9%
- Veröffentlicht 01.09.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 08:35:42
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
CVE-2022-25978
- EPSS 0.53%
- Veröffentlicht 15.02.2023 05:15:11
- Zuletzt bearbeitet 18.03.2025 16:15:12
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external resources, which allows malicious actors to introduce links starting with a javascript: scheme.
CVE-2023-0108
- EPSS 0.52%
- Veröffentlicht 07.01.2023 04:15:08
- Zuletzt bearbeitet 21.11.2024 07:36:34
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0106
- EPSS 0.65%
- Veröffentlicht 07.01.2023 04:15:08
- Zuletzt bearbeitet 21.11.2024 07:36:33
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0107
- EPSS 0.5%
- Veröffentlicht 07.01.2023 04:15:08
- Zuletzt bearbeitet 21.11.2024 07:36:33
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
CVE-2023-0110
- EPSS 0.5%
- Veröffentlicht 07.01.2023 04:15:08
- Zuletzt bearbeitet 21.11.2024 07:36:34
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.