Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Evernote

First CVE: May 22, 2017Active for: 9 yearsTotal CVEs: 12
42.4
VTI Score
High

Evernote operates a suite of note-taking and web-clipping applications with significant reach across desktop, mobile, and web platforms, positioning the vendor's products at the interface between user content creation and cloud synchronization. Its vulnerability profile centers on input-handling and authentication weaknesses across the core Evernote application and complementary tools such as Web Clipper, with recurring flaws in cross-site scripting, command injection, path traversal, and improper permission assignment that are characteristic of applications bridging client, web, and server tiers. A meaningful share of the vendor's disclosures reach serious severity, and the weakness classes carry a moderate tendency toward public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Evernote over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2017
9 years ago
Most Recent CVE
Jan 9, 2024
927 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10038HIGH
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.app/Contents/MacOS/Cal
May 31, 20197.836NOYES
CVE-2023-50643CRITICAL
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
Jan 9, 20249.833NONO
CVE-2020-17759HIGH
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specia
Jun 24, 20218.827NONO
CVE-2019-17051HIGH
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving
Sep 30, 20197.825NONO
CVE-2018-20058HIGH
In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634.
Dec 11, 20187.525NONO
CVE-2016-4900HIGH
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
May 22, 20177.823NONO
CVE-2019-12592MEDIUM
A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome allows remote attackers to run arbitrary web script or HTML in
Jun 18, 20196.122NONO
CVE-2018-18524MEDIUM
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. After a victim opens an
May 13, 20196.122NONO
CVE-2018-20351MEDIUM
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.
Dec 22, 20186.121NONO
CVE-2018-19658MEDIUM
The Markdown editor in YXBJ before 8.3.2 on macOS has stored XSS. This behavior may be encountered by some Evernote users; however, it is a vulnerability in YXBJ, not a vulnerabili
Mar 2, 20205.420NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
50%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (33.3%)
Network7 (58.3%)
Unknown0 (0.0%)
Physical1 (8.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (33.3%)
Unknown0 (0.0%)
Required8 (66.7%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None10 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
8.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Evernote.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Evernote — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Evernote's Products

View all 2 CNAs →

Top CWEs