Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-106550 — CVE-2026-106550

Mozilla's Node-convict (version 6.2.2 and later) is vulnerable to a Denial of Service vulnerability caused by incomplete prototype‑pollution protections in config.set(). An attacker controlling the c…

| Denial of Service
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106547 — HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata

A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. Wh…

hdf5 | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.4 MEDIUM
CVE-2026-106494 — Backstage: Improper input validation in cloud storage URL readers

Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attac…

backstage_plugin-techdocs-node | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.0 LOW
CVE-2026-106493 — Backstage: Cloud storage catalog locations may cross configured storage boundaries

Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename object…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.6 HIGH
CVE-2026-106492 — Backstage: Improper preservation of access restrictions during service credential delegat…

Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during s…

backstage_plugin-techdocs-node | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.4 MEDIUM
CVE-2026-106491 — Backstage: Improper input validation in proxy-backend

Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-106490 — Backstage: Improper input validation in TechDocs static content requests

Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content reque…

backstage_plugin-techdocs-node | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-106489 — Backstage: Improper authorization enforcement for TechDocs static content

Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static con…

backstage_plugin-techdocs-node | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.1 HIGH
CVE-2026-106488 — Backstage: Improper authentication in the OIDC provider

Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc prov…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.5 LOW
CVE-2026-106487 — Backstage: Unsupported catalog cluster authentication mode in kubernetes backend

Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kub…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106486 — Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions

Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.4 MEDIUM
CVE-2026-106463 — Backstage: Improper authorization in GitLab organizational user ingestion

Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organization…

backstage_plugin-techdocs-node | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.4 MEDIUM
CVE-2026-106462 — Backstage: Scaffolder credential handling may allow unintended GitHub authentication fall…

Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user co…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-106461 — Backstage: Incorrect authorization in scaffolder task listing

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An a…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-106460 — Backstage: Explicit negative email verification can be ignored during shared OAuth profil…

Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not consistently honor explicit negative email verificati…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106459 — Backstage: Improper input validation in Sentry scaffolder actions

Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentr…

backstage_plugin-techdocs-node | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-106458 — Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates

Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository fi…

backstage_plugin-techdocs-node | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-106457 — Backstage: Insufficient audience validation in the Cloudflare Access auth provider

Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audienc…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.8 MEDIUM
CVE-2026-106456 — Backstage: Inconsistent credential enforcement for overlapping proxy routes

Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping …

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-106455 — Backstage: Improper validation of MkDocs plugin configuration in TechDocs

Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin co…

backstage_plugin-techdocs-node | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 15427 Results