Vulnerabilities (CVE)

Filtered by vendor Evernote Subscribe
Filtered by product Evernote
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-5112 1 Evernote 1 Evernote 2020-02-10 2.1 LOW 4.6 MEDIUM
Evernote before 5.5.1 has insecure PIN storage
CVE-2018-18524 1 Evernote 1 Evernote 2019-05-13 4.3 MEDIUM 6.1 MEDIUM
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an affected note under Present mode, the attacker can read the victim's files and achieve remote execution command on the victim's computer.
CVE-2018-20351 1 Evernote 1 Evernote 2019-01-09 4.3 MEDIUM 6.1 MEDIUM
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.