Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-65795 Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a craf… Memos Patch available Fix from $1,9502025-12-08 MEDIUM 6.5 CVE-2025-65797 Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify … Memos Patch available Fix from $1,6002025-12-08 MEDIUM 5.4 CVE-2025-65798 Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by oth… Memos Patch available Fix from $1,6002025-12-08 HIGH 7.5 CVE-2024-21635 Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their passw… Memos after 0.18.1 Fix from $1,9502025-11-14 MEDIUM 5.4 CVE-2025-56761 Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verif… Memos Patch available Fix from $1,6002025-09-03 CRITICAL 9.8 CVE-2025-50738 The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing su… Memos after 0.24.3 Fix from $2,3002025-07-29 CRITICAL 9.8 CVE-2025-22952 elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploite… Memos Patch available Fix from $2,3002025-02-27 MEDIUM 5.4 CVE-2023-0109 A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a J… Memos Patch available Fix from $1,6002024-11-15 HIGH 8.1 CVE-2024-41659 memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is re… Memos 0.21.0+ Fix from $1,9502024-08-20 MEDIUM 6.1 CVE-2024-29029 memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthentica… Memos 0.22.0+ Fix from $1,6002024-04-19 MEDIUM 5.3 CVE-2024-29028 memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthent… Memos 0.16.1+ Fix from $1,6002024-04-19 MEDIUM 5.3 CVE-2024-29030 memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticat… Memos 0.22.0+ Fix from $1,6002024-04-19 HIGH 8.8 CVE-2023-5036 Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1. Memos 0.15.1+ Fix from $1,9502023-09-18 HIGH 8.8 CVE-2023-4697 Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2. Memos 0.13.2+ Fix from $1,9502023-09-01 HIGH 7.5 CVE-2023-4698 Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2. Memos 0.13.2+ Fix from $1,9502023-09-01 CRITICAL 9.8 CVE-2023-4696 Improper Access Control in GitHub repository usememos/memos prior to 0.13.2. Memos 0.13.2+ Fix from $2,3002023-09-01 MEDIUM 6.1 CVE-2022-25978 All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external reso… Memos Patch available Fix from $1,6002023-02-15 MEDIUM 5.4 CVE-2023-0106 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. Memos 0.10.0+ Fix from $1,6002023-01-07 MEDIUM 5.4 CVE-2023-0107 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. Memos 0.10.0+ Fix from $1,6002023-01-07 MEDIUM 5.4 CVE-2023-0108 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. Memos 0.10.0+ Fix from $1,6002023-01-07 MEDIUM 5.4 CVE-2023-0110 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. Memos 0.10.0+ Fix from $1,6002023-01-07 MEDIUM 5.4 CVE-2023-0111 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. Memos 0.10.0+ Fix from $1,6002023-01-07 MEDIUM 5.4 CVE-2023-0112 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0. Memos 0.10.0+ Fix from $1,6002023-01-07 CRITICAL 9.0 CVE-2022-4866 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $2,3002022-12-31 CRITICAL 9.0 CVE-2022-4865 Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $2,3002022-12-31 MEDIUM 6.5 CVE-2022-4863 Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-30 HIGH 8.8 CVE-2022-4844 Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,9502022-12-29 MEDIUM 6.5 CVE-2022-4846 Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-29 MEDIUM 6.5 CVE-2022-4847 Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-29 MEDIUM 6.5 CVE-2022-4849 Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. Memos 0.9.1+ Fix from $1,6002022-12-29