VulnSea

Daily digest

Sunday 30 November 2025

A heavy day: 14 new CVEs, well above the recent average of about 4. Of those, 4 high.

14
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2025-13792High· 7.3
10mo ago

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97

A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros …

▾ TwilightEPSS 0.46%via NVD
CVE-2025-13788High· 7.3
10mo ago

A vulnerability has been found in Chanjet CRM up to 20251106

A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. The manipulation of the argument gblOrgID leads to sql injection. The attack can be initia…

▾ Twilightchanjet · chanjet_crmEPSS 0.40%via NVD
CVE-2025-13786High· 7.3
10mo ago

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665

A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible…

▾ Twilightwtcms_project · wtcmsEPSS 0.56%via NVD
CVE-2025-66423High· 7.1
10mo ago

trytond does not enforce access rights for the route of the HTML editor.

trytond does not enforce access rights for the route of the HTML editor.

▾ Twilighttrytond · trytondEPSS 0.23%via OSV
CVE-2025-66424Medium· 6.5
10mo ago

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export

Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

▾ Sunlittryton · trytondEPSS 0.24%via NVD
CVE-2025-13791Medium· 6.3
10mo ago

A vulnerability was identified in Scada-LTS up to 2.7.8.1

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversa…

▾ Sunlitscada-lts · scada-ltsEPSS 0.47%via NVD
CVE-2025-13789Medium· 6.3
10mo ago

A vulnerability was found in ZenTao up to 21.7.6-8564

A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model.php. The manipulation of the argument Base results in server-side request forgery. The attack can be launched remote…

▾ Sunlitzentao · zentaoEPSS 0.29%via NVD
CVE-2025-13787Medium· 5.4
10mo ago

A flaw has been found in ZenTao up to 21.7.6-8564

A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper pr…

▾ Sunlitzentao · zentaoEPSS 0.38%via NVD
CVE-2025-66422Medium· 4.3
10mo ago

trytond allows remote attackers to obtain sensitive trace-back (server setup) information

trytond allows remote attackers to obtain sensitive trace-back (server setup) information

▾ Sunlittrytond · trytondEPSS 0.29%via OSV
CVE-2025-13793Medium· 4.3
10mo ago

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter …

▾ SunlitEPSS 0.32%via NVD
CVE-2025-13790Medium· 4.3
10mo ago

A vulnerability was determined in Scada-LTS up to 2.7.8.1

A vulnerability was determined in Scada-LTS up to 2.7.8.1. This impacts an unknown function. This manipulation causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be ut…

▾ Sunlitscada-lts · scada-ltsEPSS 0.26%via NVD
CVE-2025-13785Medium· 4.3
10mo ago

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5

A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects some unknown processing of the file /user/profile of the component Image Handler. Such manipulation leads to informatio…

▾ Sunlityungifez · skuulEPSS 0.37%via NVD

Most-affected vendors

By CVEs published in the period.