Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2025-12744 | A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell command (docker inspect %s) without proper validation. An unprivileged local user can craft a payload that injects shell metacharacters, causing the root-running ABRT process to execute attacker-controlled commands and ultimately gain full root privileges. | 8.8 | 0.56% | 2025-12-03 | 2026-06-17 |
| CVE-2023-39178 | Rejected reason: Duplicate of CVE-2023-52441. | N/A | N/A | 2025-10-29 | 2025-10-29 |
| CVE-2023-39177 | Rejected reason: Duplicate of CVE-2023-52442. | N/A | N/A | 2025-10-29 | 2025-10-29 |
| CVE-2025-62401 | An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment. | 5.4 | 0.19% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62400 | Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information. | 4.3 | 0.25% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62399 | Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks. | 7.5 | 0.35% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62398 | A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts. | 5.4 | 0.21% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62397 | The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance. | 5.3 | 0.25% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62396 | An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured. | 5.3 | 0.27% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62395 | A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data. | 4.3 | 0.21% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62394 | Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive users might receive quiz-related messages, leaking limited course information. | 4.3 | 0.19% | 2025-10-23 | 2026-06-17 |
| CVE-2025-62393 | A flaw was found in the course overview output function where user access permissions were not fully enforced. This could allow unauthorized users to view information about courses they should not have access to, potentially exposing limited course details. | 4.3 | 0.20% | 2025-10-23 | 2026-06-17 |
| CVE-2023-5342 | The Fedora Secure Boot CA certificate shipped with shim in Fedora was expired which could lead to old or invalid signed boot components being loaded. | 4.1 | 0.08% | 2025-08-14 | 2026-06-17 |
| CVE-2024-4982 | A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server. | 7.6 | 0.70% | 2025-05-12 | 2026-06-17 |
| CVE-2024-4981 | A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo. | 7.6 | 0.34% | 2025-05-12 | 2026-06-17 |
| CVE-2023-4533 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. It was assigned as a duplicate of CVE-2023-52440 | N/A | N/A | 2025-04-30 | 2025-04-30 |
| CVE-2025-3647 | A flaw was discovered in Moodle. Additional checks were required to ensure that users can only access cohort data they are authorized to retrieve. | 4.3 | 0.26% | 2025-04-25 | 2026-06-17 |
| CVE-2025-3645 | A flaw was found in Moodle. Insufficient capability checks in a messaging web service allowed users to view other users' names and online statuses. | 4.3 | 0.29% | 2025-04-25 | 2026-06-17 |
| CVE-2025-3644 | A flaw was found in Moodle. Additional checks were required to prevent users from deleting course sections they did not have permission to modify. | 4.3 | 0.26% | 2025-04-25 | 2026-06-17 |
| CVE-2025-3643 | A flaw was found in Moodle. The return URL in the policy tool required additional sanitizing to prevent a reflected Cross-site scripting (XSS) risk. | 5.4 | 0.27% | 2025-04-25 | 2026-06-17 |