Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.93%—Tt-rss Tiny Tiny RSS13/3/202117/6/2026
The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code without a valid password. NOTE: this issue only affected the git master branch for a short time. However, all end users are explicitly directed to use the git master branch in production. Semantic…
ModificadaMedia (6.1)0.88%—Tt-rss Tiny Tiny RSS19/9/202017/6/2026
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document.
ModificadaAlta (8.1)1.2%—Tt-rss Tiny Tiny RSS19/9/202017/6/2026
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. imgproxy in plugins/af_proxy_http/init.php mishandles $_REQUEST["url"] in an error message.
ModificadaCrítica (9.8)18%—Tt-rss Tiny Tiny RSS19/9/202017/6/2026
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting them.
ModificadaCrítica (9.8)1.5%—Tt-rss Tiny Tiny RSS20/11/201717/6/2026
A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.
ModificadaMedia (6.1)0.89%—Tt-rss Tiny Tiny RSS17/7/201717/6/2026
Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack