Skip to content
Noroxi

usememos records

73 published records for vendor usememos.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
93.2%
Median publish → KEV
No record has entered KEV

All records

73 records
  • elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    usememos · memosFeb 27, 2025

  • The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs.

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    usememos · memosJul 29, 2025

  • CVE-2023-4696
    39Monitor

    Improper Access Control in usememos/memos

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    usememos · memosAug 31, 2023

  • CVE-2022-4686
    39Monitor

    Authorization Bypass Through User-Controlled Key in usememos/memos

    CriticalCVSS 9.8No exploitEPSS 1%

    usememos · memosDec 23, 2022

  • CVE-2022-4865
    36Monitor

    Cross-site Scripting (XSS) - Stored in usememos/memos

    CriticalCVSS 9.0No exploitEPSS 1%

    usememos · memosDec 31, 2022

  • CVE-2022-4866
    36Monitor

    Cross-site Scripting (XSS) - Stored in usememos/memos

    CriticalCVSS 9.0No exploitEPSS 1%

    usememos · memosDec 31, 2022

  • CVE-2022-4809
    35Monitor

    Improper Access Control in usememos/memos

    HighCVSS 8.8No exploitEPSS 1%

    usememos · memosDec 28, 2022

  • CVE-2023-4697
    35Monitor

    Improper Privilege Management in usememos/memos

    HighCVSS 8.8No exploitEPSS 1%

    usememos · memosAug 31, 2023

  • CVE-2022-4803
    35Monitor

    Authorization Bypass Through User-Controlled Key in usememos/memos

    HighCVSS 8.8No exploitEPSS 1%

    usememos · memosDec 28, 2022

  • CVE-2022-4688
    35Monitor

    Improper Authorization in usememos/memos

    HighCVSS 8.8No exploitEPSS 1%

    usememos · memosDec 23, 2022

  • CVE-2022-4689
    35Monitor

    Improper Access Control in usememos/memos

    HighCVSS 8.8No exploitEPSS 1%

    usememos · memosDec 23, 2022

  • CVE-2022-4684
    35Monitor

    Improper Access Control in usememos/memos

    HighCVSS 8.8No exploitEPSS 1%

    usememos · memosDec 23, 2022

  • CVE-2022-4808
    35Monitor

    Improper Privilege Management in usememos/memos

    HighCVSS 8.8No exploitEPSS 0%

    usememos · memosDec 28, 2022

  • CVE-2023-5036
    35Monitor

    Cross-Site Request Forgery (CSRF) in usememos/memos

    HighCVSS 8.8No exploitEPSS 0%

    usememos · memosSep 18, 2023

  • CVE-2022-4844
    35Monitor

    Cross-Site Request Forgery (CSRF) in usememos/memos

    HighCVSS 8.8No exploitEPSS 0%

    usememos · memosDec 29, 2022

  • CVE-2022-4796
    32Monitor

    Incorrect Use of Privileged APIs in usememos/memos

    HighCVSS 8.1No exploitEPSS 1%

    usememos · memosDec 28, 2022

  • GHSL-2024-034: memos CORS Misconfiguration in server.go

    HighCVSS 8.1No exploitEPSS 1%

    usememos · memosAug 20, 2024

  • CVE-2022-4687
    32Monitor

    Incorrect Use of Privileged APIs in usememos/memos

    HighCVSS 8.1No exploitEPSS 1%

    usememos · memosDec 23, 2022

  • CVE-2023-4698
    30Monitor

    Improper Input Validation in usememos/memos

    HighCVSS 7.5Proof of conceptEPSS 1%

    usememos · memosAug 31, 2023

  • CVE-2022-4767
    30Monitor

    Denial of Service in usememos/memos

    HighCVSS 7.5No exploitEPSS 1%

    usememos · memosDec 27, 2022

  • Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts v

    HighCVSS 7.5No exploitEPSS 0%

    usememos · memosDec 8, 2025

  • Memos Access Tokens Stay Valid after User Password Change

    HighCVSS 7.1No exploitEPSS 0%

    usememos · memosNov 14, 2025

  • CVE-2022-4799
    26Monitor

    Authorization Bypass Through User-Controlled Key in usememos/memos

    MediumCVSS 6.5No exploitEPSS 1%

    usememos · memosDec 28, 2022

  • CVE-2022-4863
    26Monitor

    Improper Handling of Insufficient Permissions or Privileges in usememos/memos

    MediumCVSS 6.5No exploitEPSS 1%

    usememos · memosDec 30, 2022

  • CVE-2022-4847
    26Monitor

    Incorrectly Specified Destination in a Communication Channel in usememos/memos

    MediumCVSS 6.5No exploitEPSS 1%

    usememos · memosDec 29, 2022