CVE-2025-13795 – codingWithElias School Management System Edit Student Info student-view.php cross site scripting

The following table lists the changes that have been made to the CVE-2025-13795 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 30, 2025 Action […]

CVE-2025-35028 – HexStrike AI MCP Server Command Injection

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the […]

CVE-2025-13793 – winston-dsouza Ecommerce-Website GET Parameter header_menu.php cross site scripting

The following table lists the changes that have been made to the CVE-2025-13793 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 30, 2025 Action […]

CVE-2025-13792 – Qualitor getResumo.php eval code injection

The following table lists the changes that have been made to the CVE-2025-13792 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 30, 2025 Action […]

CVE-2025-13791 – Scada-LTS Project Import ZIPProjectManager.java Common.getHomeDir path traversal

The following table lists the changes that have been made to the CVE-2025-13791 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 30, 2025 Action […]

CVE-2025-13790 – Scada-LTS cross-site request forgery

Affected Products The following products are affected by CVE-2025-13790 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-13789 – ZenTao model.php makeRequest server-side request forgery

The following table lists the changes that have been made to the CVE-2025-13789 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Nov. 30, 2025 Action […]

CVE-2025-13788 – Chanjet CRM upgradeattribute.php sql injection

Affected Products The following products are affected by CVE-2025-13788 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV Nov 30, 2025Ravie LakshmananHacktivism / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include a sec … Read more Published Date: Nov 30, 2025 (1 hour, 58 minutes ago) Vulnerabilities has been mentioned in this […]