Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2025-0577 | An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions. | 4.8 | 0.24% | 2026-02-18 | 2026-06-17 |
| CVE-2025-14282 | A flaw was found in Dropbear. When running in multi-user mode and authenticating users, the dropbear ssh server does the socket forwardings requested by the remote client as root, only switching to the logged-in user upon spawning a shell or performing some operations like reading the user's files. With the recent ability of also using unix domain sockets as the forwarding destination any user able to log in via ssh can connect to any unix socket with the root's credentials, bypassing both file | 5.4 | 0.36% | 2026-02-12 | 2026-06-17 |
| CVE-2025-67857 | A flaw was found in moodle. During anonymous assignment submissions, user identifiers were inadvertently exposed in URLs. This data exposure allows unauthorized viewers to see internal user IDs, compromising the intended anonymity and potentially leading to information disclosure. | 4.3 | 0.34% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67856 | A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awarding process, allowed badges to be granted without proper verification. This could enable unauthorized users to obtain badges they are not entitled to, potentially leading to privilege escalation or unauthorized access to certain features. | 5.4 | 0.27% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67855 | A flaw was found in mooodle. A remote attacker could exploit a reflected Cross-Site Scripting (XSS) vulnerability in the policy tool return URL. This vulnerability arises from insufficient sanitization of URL parameters, allowing attackers to inject malicious scripts through specially crafted links. Successful exploitation could lead to information disclosure or arbitrary client-side script execution within the user's browser. | 5.4 | 0.33% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67853 | A flaw was found in Moodle. A remote attacker could exploit a lack of proper rate limiting in the confirmation email service. This vulnerability allows attackers to more easily enumerate or guess user credentials, facilitating brute-force attacks against user accounts. | 7.5 | 0.42% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67852 | A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure. | 3.5 | 0.25% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67851 | A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet. | 6.1 | 0.25% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67850 | A flaw was found in moodle. This vulnerability, known as Cross-Site Scripting (XSS), occurs due to insufficient checks on user-provided data in the formula editor's arithmetic expression fields. A remote attacker could inject malicious code into these fields. When other users view these expressions, the malicious code would execute in their web browsers, potentially compromising their data or leading to unauthorized actions. | 7.3 | 0.29% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67849 | A flaw was found in Moodle. This cross-site scripting (XSS) vulnerability, caused by improper sanitization of AI prompt responses, allows attackers to inject malicious HTML or script into web pages. When other users view these compromised pages, their sessions could be stolen, or the user interface could be manipulated. | 7.3 | 0.23% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67848 | A flaw was found in Moodle. This authentication bypass vulnerability allows suspended users to authenticate through the Learning Tools Interoperability (LTI) Provider. The issue arises from the LTI authentication handlers failing to enforce the user's suspension status, enabling unauthorized access to the system. This can lead to information disclosure or other unauthorized actions by users who should be restricted. | 8.1 | 0.37% | 2026-02-03 | 2026-06-17 |
| CVE-2025-67847 | A flaw was found in Moodle. An attacker with access to the restore interface could trigger server-side execution of arbitrary code. This is due to insufficient validation of restore input, which leads to unintended interpretation by core restore routines. Successful exploitation could result in a full compromise of the Moodle application. | 8.8 | 0.53% | 2026-01-23 | 2026-06-17 |
| CVE-2025-3839 | A flaw was found in Epiphany, a tool that allows websites to open external URL handler applications with minimal user interaction. This design can be misused to exploit vulnerabilities within those handlers, making them appear remotely exploitable. The browser fails to properly warn or gate this action, resulting in potential code execution on the client device via trusted UI behavior. | 8.0 | 0.38% | 2026-01-23 | 2026-06-17 |
| CVE-2026-0710 | A flaw was found in SIPp. A remote attacker could exploit this by sending specially crafted Session Initiation Protocol (SIP) messages during an active call. This vulnerability, a NULL pointer dereference, can cause the application to crash, leading to a denial of service. Under specific conditions, it may also allow an attacker to execute unauthorized code, compromising the system's integrity and availability. | 8.4 | 0.22% | 2026-01-22 | 2026-06-17 |
| CVE-2025-69195 | A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker can exploit this by providing a specially crafted URL, which, upon user interaction with wget2, can lead to memory corruption. This can cause the application to crash and potentially allow for further malicious activities. | 7.6 | 0.29% | 2026-01-09 | 2026-06-17 |
| CVE-2025-69194 | A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An attacker can abuse this behavior to write files to unintended locations on the system. This can lead to data loss or potentially allow further compromise of the user’s environment. | 8.8 | 0.71% | 2026-01-09 | 2026-06-17 |
| CVE-2024-10398 | Rejected reason: This CVE id was assigned but later discarded. | N/A | N/A | 2025-12-23 | 2025-12-23 |
| CVE-2023-5094 | Rejected reason: This CVE id was assigned to an issue which was later deemed not security relevant. | N/A | N/A | 2025-12-23 | 2025-12-23 |
| CVE-2023-5093 | Rejected reason: This CVE id was assigned to an issue which was later deemed not security relevant. | N/A | N/A | 2025-12-23 | 2025-12-23 |
| CVE-2023-5092 | Rejected reason: This CVE id was assigned to an issue which was later deemed not security relevant. | N/A | N/A | 2025-12-23 | 2025-12-23 |