Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

64 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)0.26%—Backstage Plugin Techdocs NodeAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a…
Pendiente de análisisMedia (5.3)0.28%—Backstage Plugin Techdocs NodeAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving…
Pendiente de análisisMedia (5.3)0.28%—Backstage Plugin Techdocs NodeAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to…
Pendiente de análisisMedia (5.3)0.22%—Backstage Plugin-scaffolder-backendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer…
Pendiente de análisisAlta (7.7)0.27%—Backstage Plugin Techdocs NodeAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs…
Pendiente de análisisMedia (6.5)0.25%—Backstage Plugin-scaffolder-backendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in…
Pendiente de análisisAlta (8.1)0.36%—Backstage Plugin Scaffolder BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action…
Pendiente de análisisMedia (5.3)0.28%—Backstage Plugin-scaffolder-backendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used…
Pendiente de análisisCrítica (9.6)0.47%—Backstage Plugin Scaffolder BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution…
Pendiente de análisisAlta (8.5)0.33%—Backstage Plugin Scaffolder BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific…
Pendiente de análisisMedia (4.9)0.27%—Backstage Plugin Scaffolder BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder…
Pendiente de análisisAlta (7.7)0.31%—Backstage Plugin Catalog BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder…
Pendiente de análisisMedia (4.3)0.19%—Backstage Plugin Catalog BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated…
Pendiente de análisisBaja (3.1)0.21%—Backstage Plugin Catalog BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended…
Pendiente de análisisMedia (4.4)0.29%—Backstage Backend DefaultsAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud storage bucket used by Backstage could craft object names that could collide with…
Pendiente de análisisBaja (3)0.26%—Linuxfoundation BackstageAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename objects in a configured Azure Blob Storage or AWS S3 catalog source could cause catalog descriptors to be read from outside…
Pendiente de análisisAlta (7.6)0.24%—Backstage Backend DefaultsAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could…
Pendiente de análisisMedia (6.4)0.27%—Backstage Plugin Proxy BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the…
Pendiente de análisisMedia (6.5)0.36%—Backstage Plugin Techdocs BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content requests. When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs…
Pendiente de análisisMedia (6.5)0.29%—Backstage Plugin Techdocs BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An authenticated user with access to one TechDocs documentation site could craft a URL able to read documentation…
Pendiente de análisisAlta (8.1)0.28%—Backstage Plugin-auth-backend-module-oidc-providerAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may…
Pendiente de análisisBaja (3.5)0.22%—Backstage Plugin Kubernetes BackendAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or…
Pendiente de análisisAlta (8.5)0.33%—Backstage Plugin Scaffolder Backend Module Bitbucket CloudAIBackstage Plugin Scaffolder Backend Module Bitbucket ServerAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An…
Pendiente de análisisMedia (5.4)0.17%—Backstage Plugin Catalog Backend Module GitlabAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organizational user ingestion. Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an…
Pendiente de análisisMedia (6.4)0.17%—Linuxfoundation BackstageAI6/10/20267/10/2026
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access…
Orbitaley — Vulnerabilidades