CVEs affecting projects tracked on Release Alert, from NVD & OSV.
In Moodle 3.x, there is XSS in the assignment submission page.