6.5

CVSS3.1

CVE-2026-33903 - Ella Core panics when processing a crafted NGAP LocationReport message

Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted NGAP LocationReport message. An attacker able to send crafted NGAP messages to Ella Core can crash the process, causing service disruption for all connected subscribers. Version 1…

πŸ“… Published: March 27, 2026, 8:52 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.4

CVSS3.1

CVE-2026-33896 - Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` ext…

πŸ“… Published: March 27, 2026, 8:50 p.m. πŸ”„ Last Modified: March 30, 2026, 7:16 p.m.

7.5

CVSS3.1

CVE-2026-33895 - Forge has signature forgery in Ed25519 due to missing S > L check

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scalar S is not reduced modulo the group order (`S >= L`). A valid signature and its `S + L…

πŸ“… Published: March 27, 2026, 8:47 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

7.5

CVSS3.1

CVE-2026-33894 - Forge has signature forgery in RSA-PKCS due to ASN.1 extra field

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent keys (e=3). Attackers can forge signatures by stuffing β€œgarbage” bytes within th…

πŸ“… Published: March 27, 2026, 8:45 p.m. πŸ”„ Last Modified: March 31, 2026, 2:05 p.m.

7.5

CVSS3.1

CVE-2026-33891 - Forge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input

Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an infinite loop in the BigInteger.modInverse() function (inherited from the bundled jsbn li…

πŸ“… Published: March 27, 2026, 8:43 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.

4.2

CVSS3.1

CVE-2026-32187 - Microsoft Edge (Chromium-based) Defense in Depth Vulnerability

Microsoft Edge (Chromium-based) Defense in Depth Vulnerability

πŸ“… Published: March 27, 2026, 8:42 p.m. πŸ”„ Last Modified: March 31, 2026, 2:03 p.m.

5.4

CVSS3.1

CVE-2026-33887 - Statamic allows unauthorized content access through missing authorization in its revision controlle…

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticated Control Panel users could view entry revisions for any collection with revisions enabled, regardless of whether they had the required collection permissions. This bypasses the a…

πŸ“… Published: March 27, 2026, 8:41 p.m. πŸ”„ Last Modified: March 30, 2026, 6:54 p.m.

6.5

CVSS3.1

CVE-2026-33886 - Statamic's sensitive configuration values are exposed to content editors via Antlers-enabled fields

Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions 5.73.16 and 6.7.2, a control panel user with access to Antlers-enabled fields could access sensitive application configuration values by inserting config variables into their cont…

πŸ“… Published: March 27, 2026, 8:40 p.m. πŸ”„ Last Modified: March 31, 2026, 6:54 p.m.

6.1

CVSS3.1

CVE-2026-33885 - Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions an…

πŸ“… Published: March 27, 2026, 8:39 p.m. πŸ”„ Last Modified: March 31, 2026, 2 p.m.

4.3

CVSS3.1

CVE-2026-33884 - Statamic's live preview token bypasses content protection for unrelated entries

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenticated Control Panel user with access to live preview could use a live preview token to access restricted content that the token was not intended for. This has been fixed in 5.73.16…

πŸ“… Published: March 27, 2026, 8:38 p.m. πŸ”„ Last Modified: March 30, 2026, 1:26 p.m.
Total resulsts: 341475
Page 55 of 34,148
Β« previous page Β» next page
Filters