|
1391
|
7.5 |
HIGH
Network
|
fedify
|
fedify\/fedify fedify\/vocab-runtime
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8, and 2.1.1, @fedify/fedify follows HTTP redirects recursively in its remote doc…
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-34148
|
2026-04-26 03:03 |
2026-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1392
|
6.5 |
MEDIUM
Network
|
mattermost
|
mattermost_server
|
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-21388
|
2026-04-26 03:02 |
2026-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1393
|
3.7 |
LOW
Network
|
linuxfoundation
|
backstage\/backend_defaults
|
Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24048
|
2026-04-26 03:01 |
2026-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1394
|
3.7 |
LOW
Network
|
linuxfoundation
|
backstage\/backend_defaults
|
Backstage es un framework abierto para construir portales de desarrolladores, y @backstage/backend-defaults proporciona las implementaciones y configuración predeterminadas para una aplicación backen…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-24048
|
2026-04-26 03:01 |
2026-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1395
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL parsing used by Backstage integrations allowed path traversal sequences in encod…
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1396
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 1.20.1, una vulnerabilidad en el análisis de URL de SCM utilizado por las integraciones de Backstage …
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1397
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run throug…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1398
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 3.1.4, una plantilla de andamiaje maliciosa puede eludir el mecanismo de redacción de registros para …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1399
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1400
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.x antes de 4.4.1, existe potencial ejecución remota de código y robo de credenciales de cuenta debido a una vulnerabilidad de suplantación de identidad.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|