MikeTrendsTrends right now

search

CVSS

Trends

  1. 1
    Medium-severity vulnerability disclosed in Backstage plugin-proxy-backendโ—๐Ÿšจ EUVD-2026-93989 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: plugin-proxy-backend, backstage ๐Ÿข Vendor: @ backstage , backstaMmastodonTechnologyCybersecurity026 min ago

    A new vulnerability, EUVD-2026-93989, has been disclosed affecting the @backstage/plugin-proxy-backend package, part of Backstage, the open-source framework for building developer portals. Versions from 0.5.0 until 0.6.18 are affected. The flaw carries a CVSS v3.1 score of 4.8 out of 10, marking it as a medium-severity issue, and was updated in the EUVD database on 2026-10-06.

  2. 2
    Moderate security flaw disclosed in Backstage Cloudflare Access pluginโ—๐Ÿšจ EUVD-2026-93990 ๐Ÿ“Š Score: 6.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: backstage, plugin-auth-backend-module-cloudflare-access-provideMmastodonTechnologyCybersecurity026 min ago

    A new vulnerability, EUVD-2026-93990, has been catalogued affecting the Cloudflare Access authentication provider plugin for Backstage, the open-source framework for building developer portals maintained under the Backstage project. Versions 0.1.0 through 0.5.0 are affected. The flaw carries a CVSS v3.1 score of 6.8, marking it as a moderate-severity issue. The advisory was updated on 6 October 2026, and administrators running the plugin are advised to check for patched releases.

  3. 3
    High-severity heap overflow vulnerability disclosed in HDF5โ—๐Ÿšจ EUVD-2026-93991 ๐Ÿ“Š Score: 8.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HDF5 ๐Ÿข Vendor: The HDF Group ๐Ÿ“… Updated: 2026-10-06 ๐Ÿ“ A heap-basMmastodonTechnologyCybersecurity026 min ago

    A high-severity vulnerability, EUVD-2026-93991, has been catalogued in the HDF5 data format library maintained by The HDF Group. The flaw is a heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c affecting HDF5 versions before 2.2.0, with a CVSS v3.1 score of 8.5. It can let a remote attacker crash applications and potentially execute arbitrary code. Security feeds circulated the advisory on 6 October 2026.