Home/Product/evernote
Product

evernote

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-50643
all versions
An issue in Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableN
9.8CRITICAL
CVE-2020-17759
all versions
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrar
8.8HIGH
CVE-2018-19658
< 8.3.2
The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote users; however
5.4MEDIUM
CVE-2013-5116
< 5.5.1
Evernote prior to 5.5.1 has insecure password change
7.1HIGH
CVE-2013-5112
< 5.5.1
Evernote before 5.5.1 has insecure PIN storage
4.6MEDIUM
CVE-2019-17051
< 7.13
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files
7.8HIGH
CVE-2019-12592
< 7.11.1
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote
6.1MEDIUM
CVE-2019-10038
all versions
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as t
7.8HIGH
CVE-2018-18524
all versions
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.j
6.1MEDIUM
CVE-2018-20351
< 8.3.2
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.
6.1MEDIUM
CVE-2018-20058
< 7.6
In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.
7.5HIGH
CVE-2016-4900
<= 6.2.1
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a
7.8HIGH
threatengine.sh