Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2021-28373
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE…
Tiny Tiny Rss
2021-03-12+
MEDIUM 6.1
CVE-2020-25789
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
Tiny Tiny Rss
2020-09-16+
CRITICAL 9.8
CVE-2020-25787EPSS 18%
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
Tiny Tiny Rss
2020-09-16+
HIGH 8.1
CVE-2020-25788
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an…
Tiny Tiny Rss
2020-09-16+
CRITICAL 9.8
CVE-2017-16896
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
Tiny Tiny Rss
Patch available
MEDIUM 6.1
CVE-2017-1000035
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack
Tiny Tiny Rss
Mitigation only