Post

2025-12-18 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2014-3146n/a - n/aIncomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.CNA n/a CVSS3.1: 5.4 - MEDIUM0 1 2 3 4 5 6 7 8 9 10 11 12 13Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2025-12689Mattermost - MattermostMattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.CVSS3.1: 6.5 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialDoS in Calls plugin via malformed UTF-8 in WebSocket requestgithub
CVE-2024-29371n/a - n/aIn jose4j before 0.9.5, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio. When this token is processed by the server, it results in significant memory allocation and processing time during decompression.CNA n/a CVSS3.1: 7.5 - HIGH0Exploitation: pocAutomatable: yesTechnical Impact: partialundefinedgithub
CVE-2025-14727F5 - NGINX Ingress ControllerA vulnerability exists in NGINX Ingress Controller’s nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.CVSS3.1: 8.3 - HIGH CVSS4.0: 8.7 - HIGH0Exploitation: noneAutomatable: noTechnical Impact: partialNGINX Ingress Controller vulnerabilitygithub
This post is licensed under CC BY 4.0 by the author.