Записи usememos
73 опубликованных записей вендора usememos.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 93,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-284 Improper Access Control11
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-648 Incorrect Use of Privileged APIs3
- CWE-918 Server-Side Request Forgery (SSRF)3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
73 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2025-22952Proof of concept | elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can beusememos · memos · CWE-918 | Критическая9,8 | — | 2,9 % | 27 февр. 2025 г. |
40В плане | CVE-2025-50738Proof of concept | The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs.usememos · memos · CWE-200 | Критическая9,8 | — | 2,2 % | 29 июл. 2025 г. |
39Наблюдать | CVE-2023-4696Proof of concept | Improper Access Control in usememos/memosusememos · memos · CWE-284 | Критическая9,8 | — | 1,1 % | 31 авг. 2023 г. |
39Наблюдать | CVE-2022-4686Эксплойта нет | Authorization Bypass Through User-Controlled Key in usememos/memosusememos · memos · CWE-639 | Критическая9,8 | — | 0,7 % | 23 дек. 2022 г. |
36Наблюдать | CVE-2022-4865Эксплойта нет | Cross-site Scripting (XSS) - Stored in usememos/memosusememos · memos · CWE-79 | Критическая9,0 | — | 1,0 % | 31 дек. 2022 г. |
36Наблюдать | CVE-2022-4866Эксплойта нет | Cross-site Scripting (XSS) - Stored in usememos/memosusememos · memos · CWE-79 | Критическая9,0 | — | 1,0 % | 31 дек. 2022 г. |
35Наблюдать | CVE-2022-4809Эксплойта нет | Improper Access Control in usememos/memosusememos · memos · CWE-284 | Высокая8,8 | — | 0,9 % | 28 дек. 2022 г. |
35Наблюдать | CVE-2023-4697Эксплойта нет | Improper Privilege Management in usememos/memosusememos · memos · CWE-269 | Высокая8,8 | — | 0,8 % | 31 авг. 2023 г. |
35Наблюдать | CVE-2022-4803Эксплойта нет | Authorization Bypass Through User-Controlled Key in usememos/memosusememos · memos · CWE-639 | Высокая8,8 | — | 0,8 % | 28 дек. 2022 г. |
35Наблюдать | CVE-2022-4688Эксплойта нет | Improper Authorization in usememos/memosusememos · memos · CWE-285 | Высокая8,8 | — | 0,7 % | 23 дек. 2022 г. |
35Наблюдать | CVE-2022-4689Эксплойта нет | Improper Access Control in usememos/memosusememos · memos · CWE-284 | Высокая8,8 | — | 0,7 % | 23 дек. 2022 г. |
35Наблюдать | CVE-2022-4684Эксплойта нет | Improper Access Control in usememos/memosusememos · memos · CWE-284 | Высокая8,8 | — | 0,6 % | 23 дек. 2022 г. |
35Наблюдать | CVE-2022-4808Эксплойта нет | Improper Privilege Management in usememos/memosusememos · memos · CWE-269 | Высокая8,8 | — | 0,4 % | 28 дек. 2022 г. |
35Наблюдать | CVE-2023-5036Эксплойта нет | Cross-Site Request Forgery (CSRF) in usememos/memosusememos · memos · CWE-352 | Высокая8,8 | — | 0,3 % | 18 сент. 2023 г. |
35Наблюдать | CVE-2022-4844Эксплойта нет | Cross-Site Request Forgery (CSRF) in usememos/memosusememos · memos · CWE-352 | Высокая8,8 | — | 0,3 % | 29 дек. 2022 г. |
32Наблюдать | CVE-2022-4796Эксплойта нет | Incorrect Use of Privileged APIs in usememos/memosusememos · memos · CWE-648 | Высокая8,1 | — | 0,8 % | 28 дек. 2022 г. |
32Наблюдать | CVE-2024-41659Эксплойта нет | GHSL-2024-034: memos CORS Misconfiguration in server.gousememos · memos · CWE-942 | Высокая8,1 | — | 0,6 % | 20 авг. 2024 г. |
32Наблюдать | CVE-2022-4687Эксплойта нет | Incorrect Use of Privileged APIs in usememos/memosusememos · memos · CWE-648 | Высокая8,1 | — | 0,6 % | 23 дек. 2022 г. |
30Наблюдать | CVE-2023-4698Proof of concept | Improper Input Validation in usememos/memosusememos · memos · CWE-20 | Высокая7,5 | — | 0,9 % | 31 авг. 2023 г. |
30Наблюдать | CVE-2022-4767Эксплойта нет | Denial of Service in usememos/memosusememos · memos · CWE-400 | Высокая7,5 | — | 0,7 % | 27 дек. 2022 г. |
30Наблюдать | CVE-2025-65795Эксплойта нет | Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts vusememos · memos · CWE-284 | Высокая7,5 | — | 0,3 % | 8 дек. 2025 г. |
28Наблюдать | CVE-2024-21635Эксплойта нет | Memos Access Tokens Stay Valid after User Password Changeusememos · memos · CWE-287 | Высокая7,1 | — | 0,3 % | 14 нояб. 2025 г. |
26Наблюдать | CVE-2022-4799Эксплойта нет | Authorization Bypass Through User-Controlled Key in usememos/memosusememos · memos · CWE-639 | Средняя6,5 | — | 0,8 % | 28 дек. 2022 г. |
26Наблюдать | CVE-2022-4863Эксплойта нет | Improper Handling of Insufficient Permissions or Privileges in usememos/memosusememos · memos · CWE-280 | Средняя6,5 | — | 0,7 % | 30 дек. 2022 г. |
26Наблюдать | CVE-2022-4847Эксплойта нет | Incorrectly Specified Destination in a Communication Channel in usememos/memosusememos · memos · CWE-941 | Средняя6,5 | — | 0,6 % | 29 дек. 2022 г. |
- CVE-2025-2295240В плане
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be
КритическаяCVSS 9,8Proof of conceptEPSS 3 %usememos · memos27 февр. 2025 г.
- CVE-2025-5073840В плане
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %usememos · memos29 июл. 2025 г.
- CVE-2023-469639Наблюдать
Improper Access Control in usememos/memos
КритическаяCVSS 9,8Proof of conceptEPSS 1 %usememos · memos31 авг. 2023 г.
- CVE-2022-468639Наблюдать
Authorization Bypass Through User-Controlled Key in usememos/memos
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %usememos · memos23 дек. 2022 г.
- CVE-2022-486536Наблюдать
Cross-site Scripting (XSS) - Stored in usememos/memos
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %usememos · memos31 дек. 2022 г.
- CVE-2022-486636Наблюдать
Cross-site Scripting (XSS) - Stored in usememos/memos
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %usememos · memos31 дек. 2022 г.
- CVE-2022-480935Наблюдать
Improper Access Control in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usememos · memos28 дек. 2022 г.
- CVE-2023-469735Наблюдать
Improper Privilege Management in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usememos · memos31 авг. 2023 г.
- CVE-2022-480335Наблюдать
Authorization Bypass Through User-Controlled Key in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usememos · memos28 дек. 2022 г.
- CVE-2022-468835Наблюдать
Improper Authorization in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usememos · memos23 дек. 2022 г.
- CVE-2022-468935Наблюдать
Improper Access Control in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usememos · memos23 дек. 2022 г.
- CVE-2022-468435Наблюдать
Improper Access Control in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %usememos · memos23 дек. 2022 г.
- CVE-2022-480835Наблюдать
Improper Privilege Management in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %usememos · memos28 дек. 2022 г.
- CVE-2023-503635Наблюдать
Cross-Site Request Forgery (CSRF) in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %usememos · memos18 сент. 2023 г.
- CVE-2022-484435Наблюдать
Cross-Site Request Forgery (CSRF) in usememos/memos
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %usememos · memos29 дек. 2022 г.
- CVE-2022-479632Наблюдать
Incorrect Use of Privileged APIs in usememos/memos
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %usememos · memos28 дек. 2022 г.
- CVE-2024-4165932Наблюдать
GHSL-2024-034: memos CORS Misconfiguration in server.go
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %usememos · memos20 авг. 2024 г.
- CVE-2022-468732Наблюдать
Incorrect Use of Privileged APIs in usememos/memos
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %usememos · memos23 дек. 2022 г.
- CVE-2023-469830Наблюдать
Improper Input Validation in usememos/memos
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %usememos · memos31 авг. 2023 г.
- CVE-2022-476730Наблюдать
Denial of Service in usememos/memos
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %usememos · memos27 дек. 2022 г.
- CVE-2025-6579530Наблюдать
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts v
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %usememos · memos8 дек. 2025 г.
- CVE-2024-2163528Наблюдать
Memos Access Tokens Stay Valid after User Password Change
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %usememos · memos14 нояб. 2025 г.
- CVE-2022-479926Наблюдать
Authorization Bypass Through User-Controlled Key in usememos/memos
СредняяCVSS 6,5Эксплойта нетEPSS 1 %usememos · memos28 дек. 2022 г.
- CVE-2022-486326Наблюдать
Improper Handling of Insufficient Permissions or Privileges in usememos/memos
СредняяCVSS 6,5Эксплойта нетEPSS 1 %usememos · memos30 дек. 2022 г.
- CVE-2022-484726Наблюдать
Incorrectly Specified Destination in a Communication Channel in usememos/memos
СредняяCVSS 6,5Эксплойта нетEPSS 1 %usememos · memos29 дек. 2022 г.