|
2841
|
2.7 |
LOW
Network
|
linuxfoundation
|
backstage\/integration
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 1.20.1, una vulnerabilidad en el análisis de URL de SCM utilizado por las integraciones de Backstage …
|
CWE-22
Path Traversal
|
CVE-2026-29185
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2842
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction mechanism to exfiltrate secrets provided run throug…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2843
|
6.5 |
MEDIUM
Network
|
linuxfoundation
|
backstage\/plugin-scaffolder-backend
|
Backstage es un framework abierto para construir portales de desarrolladores. Antes de la versión 3.1.4, una plantilla de andamiaje maliciosa puede eludir el mecanismo de redacción de registros para …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-29184
|
2026-04-26 03:01 |
2026-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2844
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerability.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2845
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.x antes de 4.4.1, existe potencial ejecución remota de código y robo de credenciales de cuenta debido a una vulnerabilidad de suplantación de identidad.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59707
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2846
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59706
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2847
|
9.8 |
CRITICAL
Network
|
n2ws
|
n2w
|
En N2W antes de 4.3.2 y 4.4.0 antes de 4.4.1, la validación indebida de los parámetros de solicitud de la API permite la ejecución remota de código.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-59706
|
2026-04-26 03:01 |
2026-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2848
|
9.8 |
CRITICAL
Network
|
filigran
|
openaev
|
OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campaign and tests. Starting in version 1.0.0 and prior to version 2.0.13, OpenAEV's…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-24467
|
2026-04-26 03:00 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2849
|
8.8 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION is affected by a Cookie with Insecure, Improper, or Missing SameSite vulnerability. This can allow cookies to be sent in cross-site requests, potentially increasing exposure to cross-site r…
|
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
|
CVE-2025-52628
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2850
|
8.8 |
HIGH
Network
|
hcltech
|
aion
|
HCL AION está afectado por una Cookie con vulnerabilidad de SameSite insegura, impropia o ausente. Esto puede permitir que las cookies se envíen en peticiones entre sitios, aumentando potencialmente …
|
CWE-1275
Sensitive Cookie with Improper SameSite Attribute
|
CVE-2025-52628
|
2026-04-26 02:59 |
2026-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|