Evernote

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    7
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-12489

    evernote-mcp-server openBrowser Command Injection Privilege Escalation Vulnerability

    Last Modified: Apr 15, 2026
    Published: Nov 06, 2025

    CVE-2023-50643

    An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.

    Last Modified: Jun 03, 2025
    Published: Jan 09, 2024

    CVE-2020-17759

    An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2021

    CVE-2018-19658

    The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote users; however, it is a vulnerability in YXBJ, not a vulnerability in Evernote.

    Last Modified: Nov 21, 2024
    Published: Mar 02, 2020

    CVE-2013-5116

    Evernote prior to 5.5.1 has insecure password change

    Last Modified: Nov 21, 2024
    Published: Jan 31, 2020
    Items Per Page
    Evernote Vulnerabilities & Security CVEs | CVE-DB