search
CVSS
Trends
- 1Medium-severity vulnerability disclosed in Backstage plugin-proxy-backendโ๐จ EUVD-2026-93989 ๐ Score: 4.8/10 (CVSS v3.1) ๐ฆ Product: plugin-proxy-backend, backstage ๐ข Vendor: @ backstage , backsta
A new vulnerability, EUVD-2026-93989, has been disclosed affecting the @backstage/plugin-proxy-backend package, part of Backstage, the open-source framework for building developer portals. Versions from 0.5.0 until 0.6.18 are affected. The flaw carries a CVSS v3.1 score of 4.8 out of 10, marking it as a medium-severity issue, and was updated in the EUVD database on 2026-10-06.
- 2Moderate security flaw disclosed in Backstage Cloudflare Access pluginโ๐จ EUVD-2026-93990 ๐ Score: 6.8/10 (CVSS v3.1) ๐ฆ Product: backstage, plugin-auth-backend-module-cloudflare-access-provide
A new vulnerability, EUVD-2026-93990, has been catalogued affecting the Cloudflare Access authentication provider plugin for Backstage, the open-source framework for building developer portals maintained under the Backstage project. Versions 0.1.0 through 0.5.0 are affected. The flaw carries a CVSS v3.1 score of 6.8, marking it as a moderate-severity issue. The advisory was updated on 6 October 2026, and administrators running the plugin are advised to check for patched releases.
- 3High-severity heap overflow vulnerability disclosed in HDF5โ๐จ EUVD-2026-93991 ๐ Score: 8.5/10 (CVSS v3.1) ๐ฆ Product: HDF5 ๐ข Vendor: The HDF Group ๐ Updated: 2026-10-06 ๐ A heap-bas
A high-severity vulnerability, EUVD-2026-93991, has been catalogued in the HDF5 data format library maintained by The HDF Group. The flaw is a heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c affecting HDF5 versions before 2.2.0, with a CVSS v3.1 score of 8.5. It can let a remote attacker crash applications and potentially execute arbitrary code. Security feeds circulated the advisory on 6 October 2026.