Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-65795
Incorrect access control in the /api/v1/user endpoint of usememos memos v0.25.2 allows unauthorized attackers to create arbitrary accounts via a craf…
Memos
Patch available
MEDIUM 6.5
CVE-2025-65797
Incorrect access control in the Identity Provider service of usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify …
Memos
Patch available
MEDIUM 5.4
CVE-2025-65798
Incorrect access control in usememos memos v0.25.2 allows attackers with low-level privileges to arbitrarily modify or delete attachments made by oth…
Memos
Patch available
HIGH 7.5
CVE-2024-21635
Memos is a privacy-first, lightweight note-taking service that uses Access Tokens to authenticate application access. When a user changes their passw…
Memos
after 0.18.1
MEDIUM 5.4
CVE-2025-56761
Memos 0.22 is vulnerable to Stored Cross site scripting (XSS) vulnerabilities by the upload attachment and user avatar features. Memos does not verif…
Memos
Patch available
CRITICAL 9.8
CVE-2025-50738
The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing su…
Memos
after 0.24.3
CRITICAL 9.8
CVE-2025-22952
elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploite…
Memos
Patch available
MEDIUM 5.4
CVE-2023-0109
A stored cross-site scripting (XSS) vulnerability was discovered in usememos/memos version 0.9.1. This vulnerability allows an attacker to upload a J…
Memos
Patch available
HIGH 8.1
CVE-2024-41659
memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is re…
Memos
0.21.0+
MEDIUM 6.1
CVE-2024-29029
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthentica…
Memos
0.22.0+
MEDIUM 5.3
CVE-2024-29028
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/httpmeta that allows unauthent…
Memos
0.16.1+
MEDIUM 5.3
CVE-2024-29030
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/resource that allows authenticat…
Memos
0.22.0+
HIGH 8.8
CVE-2023-5036
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.
Memos
0.15.1+
HIGH 8.8
CVE-2023-4697
Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.
Memos
0.13.2+
HIGH 7.5
CVE-2023-4698
Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.
Memos
0.13.2+
CRITICAL 9.8
CVE-2023-4696
Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.
Memos
0.13.2+
MEDIUM 6.1
CVE-2022-25978
All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insufficient checks on external reso…
Memos
Patch available
MEDIUM 5.4
CVE-2023-0106
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Memos
0.10.0+
MEDIUM 5.4
CVE-2023-0107
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Memos
0.10.0+
MEDIUM 5.4
CVE-2023-0108
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Memos
0.10.0+
MEDIUM 5.4
CVE-2023-0110
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Memos
0.10.0+
MEDIUM 5.4
CVE-2023-0111
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Memos
0.10.0+
MEDIUM 5.4
CVE-2023-0112
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.10.0.
Memos
0.10.0+
CRITICAL 9.0
CVE-2022-4866
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
CRITICAL 9.0
CVE-2022-4865
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 6.5
CVE-2022-4863
Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
HIGH 8.8
CVE-2022-4844
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 6.5
CVE-2022-4846
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 6.5
CVE-2022-4847
Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+
MEDIUM 6.5
CVE-2022-4849
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
Memos
0.9.1+