8.7

CVSS4.0

CVE-2019-25651 - Ubiquiti UniFi Devices Use of AES-CBC Allows Key Recovery and Unauthorized Device Control

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weakness…

πŸ“… Published: March 27, 2026, 9:16 p.m. πŸ”„ Last Modified: March 27, 2026, 10:16 p.m.

8.8

CVSS3.1

CVE-2026-33943 - Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to achieve Remote Code Execution (RCE) by injecting arbitrary JavaScript expressions in…

πŸ“… Published: March 27, 2026, 9:15 p.m. πŸ”„ Last Modified: March 27, 2026, 10:16 p.m.

8.3

CVSS3.1

CVE-2026-33941 - Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Handlebars CLI precompiler (`bin/handlebars` / `lib/precompiler.js`) concatenates user-controlled strings β€” template file names and several CLI options β€” directly into the JavaScript …

πŸ“… Published: March 27, 2026, 9:13 p.m. πŸ”„ Last Modified: March 27, 2026, 10:16 p.m.

8.1

CVSS3.1

CVE-2026-33940 - Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic par…

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafted object placed in the template context can bypass all conditional guards in `resolvePartial()` and cause `invokePartial()` to return `undefined`. The Handlebars runtime then trea…

πŸ“… Published: March 27, 2026, 9:11 p.m. πŸ”„ Last Modified: March 27, 2026, 10:16 p.m.

7.5

CVSS3.1

CVE-2026-33939 - Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. `{{*n}}`), the compiled template calls `lookupProperty(decorators, "n")`, which returns `u…

πŸ“… Published: March 27, 2026, 9:08 p.m. πŸ”„ Last Modified: March 27, 2026, 10:16 p.m.

8.1

CVSS3.1

CVE-2026-33938 - Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within a template via helpers that accept arbitrary objects. When a helper o…

πŸ“… Published: March 27, 2026, 9:05 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

9.8

CVSS3.1

CVE-2026-33937 - Handlebars.js has JavaScript Injection via AST Type Confusion

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST node is emitted directly into the generated JavaScript …

πŸ“… Published: March 27, 2026, 9:03 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

4.7

CVSS3.1

CVE-2026-33916 - Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolvePartial()` in the Handlebars runtime resolves partial names via a plain property lookup on `options.partials` without guarding against prototype-chain traversal. When `Object.prot…

πŸ“… Published: March 27, 2026, 9 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-33907 - Ella Core Panics during NAS Authentication Response/Failure with missing IEs

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connec…

πŸ“… Published: March 27, 2026, 8:58 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.2

CVSS3.1

CVE-2026-33906 - Ella Core has Privilege Escalation via Database Restore by NetworkManager role

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered…

πŸ“… Published: March 27, 2026, 8:56 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.
Total resulsts: 341034
Page 10 of 34,104
Β« previous page Β» next page
Filters