CVE List – Find High-Risk & Exploited Vulnerabilities

Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.

Assigner (CNA / source):[email protected] Remove this filter

Showing 120 of 315 results
«« First « Prev Page 1 / 16 Next »
CVE Description Max CVSS EPSS % Published Updated
CVE-2022-3675 Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows booting non-default OSTree deployments without entering a password. This allows someone with access to the GRUB menu to boot into an older version of Fedora CoreOS, reverting any secur 2.6 0.17% 2022-11-03 2026-06-17
CVE-2025-3637 A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages. 3.1 0.27% 2025-04-25 2026-06-17
CVE-2025-26532 Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored. 3.1 0.24% 2025-02-24 2026-06-17
CVE-2025-26531 Insufficient capability checks made it possible to disable badges a user does not have permission to access. 3.1 0.34% 2025-02-24 2026-06-17
CVE-2025-8860 A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, the .write callback `uefi_vars_write` is invoked. The function allocates a heap buffer without zeroing the memory, leaving the buffer filled with residual data from prior allocations. When the guest later reads from register UEFI_VARS_REG_PIO_BUFFER_TRANSFER, the .read callback `uefi_vars_read` returns leftover metadata or other sensitive process memory from the previously alloc 3.3 0.15% 2026-02-18 2026-06-17
CVE-2025-12343 A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execu 3.3 0.15% 2026-02-18 2026-06-17
CVE-2023-5551 Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups. 3.3 0.28% 2023-11-09 2026-06-17
CVE-2023-5549 Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage. 3.3 0.56% 2023-11-09 2026-06-17
CVE-2023-5548 Stronger revision number limitations were required on file serving endpoints to improve cache poisoning protection. 3.3 0.28% 2023-11-09 2026-06-17
CVE-2023-5547 The course upload preview contained an XSS risk for users uploading unsafe data. 3.3 0.51% 2023-11-09 2026-06-17
CVE-2023-5545 H5P metadata automatically populated the author with the user's username, which could be sensitive information. 3.3 0.54% 2023-11-09 2026-06-17
CVE-2023-5543 When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting. 3.3 0.24% 2023-11-09 2026-06-17
CVE-2023-5542 Students in "Only see own membership" groups could see other students in the group, which should be hidden. 3.3 0.43% 2023-11-09 2026-06-17
CVE-2023-5541 The CSV grade import method contained an XSS risk for users importing the spreadsheet, if it contained unsafe content. 3.3 0.51% 2023-11-09 2026-06-17
CVE-2025-26528 The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk. 3.4 0.27% 2025-02-24 2026-06-17
CVE-2025-67852 A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure. 3.5 0.25% 2026-02-03 2026-06-17
CVE-2025-3635 A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks. 3.5 0.15% 2025-04-25 2026-06-17
CVE-2024-25983 Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page). 3.5 0.60% 2024-02-19 2026-06-17
CVE-2024-43427 A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the export, which could result in them unintentionally being leaked if the presets are shared with a third party. 3.7 0.33% 2024-11-11 2026-06-17
CVE-2022-0333 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events. 3.8 0.56% 2022-01-25 2026-06-17
«« First « Prev Page 1 / 16 Next »
cvelogic Threat Intelligence