6.5

CVSS3.1

CVE-2026-33907 - Ella Core Panics during NAS Authentication Response/Failure with missing IEs

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Response and Authentication Failure NAS message missing IEs. An attacker able to send crafted NAS messages to Ella Core can crash the process, causing service disruption for all connec…

πŸ“… Published: March 27, 2026, 8:58 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.2

CVSS3.1

CVE-2026-33906 - Ella Core has Privilege Escalation via Database Restore by NetworkManager role

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered…

πŸ“… Published: March 27, 2026, 8:56 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-33904 - Ella Core has a Denial of Service via SCTP connection cleanup deadlock

Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification handler causes the entire AMF control plane to hang until the process is restarted. An attacker with access to the N2 interface can cause Ella Core to hang, resulting in a denial …

πŸ“… Published: March 27, 2026, 8:55 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

6.5

CVSS3.1

CVE-2026-33903 - Ella Core panics when processing a crafted NGAP LocationReport message

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. Version 1…

πŸ“… Published: March 27, 2026, 8:52 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.4

CVSS3.1

CVE-2026-33896 - Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` ext…

πŸ“… Published: March 27, 2026, 8:50 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.5

CVSS3.1

CVE-2026-33895 - Forge has signature forgery in Ed25519 due to missing S > L check

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L…

πŸ“… Published: March 27, 2026, 8:47 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.5

CVSS3.1

CVE-2026-33894 - Forge has signature forgery in RSA-PKCS due to ASN.1 extra field

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing β€œgarbage” bytes within th…

πŸ“… Published: March 27, 2026, 8:45 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

7.5

CVSS3.1

CVE-2026-33891 - Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn li…

πŸ“… Published: March 27, 2026, 8:43 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.

4.2

CVSS3.1

CVE-2026-32187 - Microsoft Edge (Chromium-based) Defense in Depth Vulnerability

Microsoft Edge (Chromium-based) Defense in Depth Vulnerability

πŸ“… Published: March 27, 2026, 8:42 p.m. πŸ”„ Last Modified: March 27, 2026, 10:33 p.m.

5.4

CVSS3.1

CVE-2026-33887 - Statamic allows unauthorized content access through missing authorization in its revision controlle…

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the a…

πŸ“… Published: March 27, 2026, 8:41 p.m. πŸ”„ Last Modified: March 27, 2026, 9:17 p.m.
Total resulsts: 341036
Page 11 of 34,104
Β« previous page Β» next page
Filters