Moodle kayıtları
moodle üreticisine ait 631 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 5 · %0,8
- Pre-auth RCE
- 26
- Düzeltme kaydı olan
- %74,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')134
- CWE-264 Permissions, Privileges, and Access Controls88
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor85
- CWE-352 Cross-Site Request Forgery (CSRF)35
- CWE-20 Improper Input Validation28
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')25
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
631 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2024-43425Silahlaştırılmış | Moodle: remote code execution via calculated question typesmoodle · moodle · CWE-94 | Yüksek8,1 | — | %87,5 | 7 Kas 2024 |
55Planlayın | CVE-2021-36393Kavram kanıtı | In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.moodle · moodle · CWE-89 | Kritik9,8 | — | %52,3 | 6 Mar 2023 |
52Planlayın | CVE-2022-0332Kavram kanıtı | A flaw was found in Moodle in versions 3.11 to 3.11.4.moodle · moodle · CWE-89 | Kritik9,8 | — | %44,9 | 25 Oca 2022 |
45Planlayın | CVE-2022-35650Kavram kanıtı | The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions.moodle · moodle · CWE-22 | Yüksek7,5 | — | %49,1 | 25 Tem 2022 |
45Planlayın | CVE-2018-1133Kavram kanıtı | An issue was discovered in Moodle 3.x.moodle · moodle · CWE-94 | Yüksek8,8 | — | %31,9 | 25 May 2018 |
43Planlayın | CVE-2021-21809Silahlaştırılmış | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10.moodle · moodle · CWE-78 | Kritik9,1 | — | %24,2 | 23 Haz 2021 |
43Planlayın | CVE-2017-2641Kavram kanıtı | In Moodle 2.x and 3.x, SQL injection can occur via user preferences.moodle · moodle · CWE-89 | Kritik9,8 | — | %14,5 | 26 Mar 2017 |
42Planlayın | CVE-2022-35649Kavram kanıtı | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code.moodle · moodle · CWE-94 | Kritik9,8 | — | %8,7 | 25 Tem 2022 |
41Planlayın | CVE-2021-36394Kavram kanıtı | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.moodle · moodle · CWE-384 | Kritik9,8 | — | %7,0 | 6 Mar 2023 |
41Planlayın | CVE-2022-30600Kavram kanıtı | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.moodle · moodle · CWE-682 | Kritik9,8 | — | %5,1 | 18 May 2022 |
41Planlayın | CVE-2004-2233İstismar yok | Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.moodle · moodle | Kritik10,0 | — | %1,7 | 31 Ara 2004 |
41Planlayın | CVE-2004-2237İstismar yok | Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."moodle · moodle | Kritik10,0 | — | %1,7 | 31 Ara 2004 |
40Planlayın | CVE-2020-14321Silahlaştırılmış | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.moodle · moodle · CWE-863 | Yüksek8,8 | — | %16,2 | 16 Ağu 2022 |
40Planlayın | CVE-2021-3943İstismar yok | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions.moodle · moodle · CWE-20 | Kritik9,8 | — | %2,5 | 22 Kas 2021 |
40Planlayın | CVE-2022-40314İstismar yok | A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.moodle · moodle · CWE-502 | Kritik9,8 | — | %2,0 | 30 Eyl 2022 |
40Planlayın | CVE-2005-2247İstismar yok | Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.moodle · moodle | Kritik10,0 | — | %1,5 | 12 Tem 2005 |
40Planlayın | CVE-2006-4936İstismar yok | Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact andmoodle · moodle · CWE-20 | Kritik10,0 | — | %1,5 | 22 Eyl 2006 |
40Planlayın | CVE-2006-4935İstismar yok | The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.moodle · moodle · CWE-20 | Kritik10,0 | — | %1,5 | 22 Eyl 2006 |
40Planlayın | CVE-2004-2236İstismar yok | Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.moodle · moodle | Kritik10,0 | — | %1,4 | 31 Ara 2004 |
40Planlayın | CVE-2004-2235İstismar yok | Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.moodle · moodle | Kritik10,0 | — | %1,4 | 31 Ara 2004 |
40Planlayın | CVE-2019-3809İstismar yok | A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.moodle · moodle · CWE-352 | Kritik10,0 | — | %0,9 | 25 Mar 2019 |
39İzleyin | CVE-2022-30599İstismar yok | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.moodle · moodle · CWE-89 | Kritik9,8 | — | %1,4 | 18 May 2022 |
39İzleyin | CVE-2023-5550İstismar yok | Moodle: rce due to lfi risk in some misconfigured shared hosting environmentsmoodle · moodle · CWE-94 | Kritik9,8 | — | %1,4 | 9 Kas 2023 |
39İzleyin | CVE-2023-28333İstismar yok | Moodle: pix helper potential mustache code injection riskmoodle · moodle · CWE-94 | Kritik9,8 | — | %1,2 | 23 Mar 2023 |
39İzleyin | CVE-2022-40315İstismar yok | A limited SQL injection risk was identified in the "browse list of users" site administration page.moodle · moodle · CWE-89 | Kritik9,8 | — | %1,0 | 30 Eyl 2022 |
- CVE-2024-4342558Planlayın
Moodle: remote code execution via calculated question types
YüksekCVSS 8,1SilahlaştırılmışEPSS %88moodle · moodle7 Kas 2024
- CVE-2021-3639355Planlayın
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
KritikCVSS 9,8Kavram kanıtıEPSS %52moodle · moodle6 Mar 2023
- CVE-2022-033252Planlayın
A flaw was found in Moodle in versions 3.11 to 3.11.4.
KritikCVSS 9,8Kavram kanıtıEPSS %45moodle · moodle25 Oca 2022
- CVE-2022-3565045Planlayın
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions.
YüksekCVSS 7,5Kavram kanıtıEPSS %49moodle · moodle25 Tem 2022
- CVE-2018-113345Planlayın
An issue was discovered in Moodle 3.x.
YüksekCVSS 8,8Kavram kanıtıEPSS %32moodle · moodle25 May 2018
- CVE-2021-2180943Planlayın
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10.
KritikCVSS 9,1SilahlaştırılmışEPSS %24moodle · moodle23 Haz 2021
- CVE-2017-264143Planlayın
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
KritikCVSS 9,8Kavram kanıtıEPSS %15moodle · moodle26 Mar 2017
- CVE-2022-3564942Planlayın
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code.
KritikCVSS 9,8Kavram kanıtıEPSS %9moodle · moodle25 Tem 2022
- CVE-2021-3639441Planlayın
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
KritikCVSS 9,8Kavram kanıtıEPSS %7moodle · moodle6 Mar 2023
- CVE-2022-3060041Planlayın
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
KritikCVSS 9,8Kavram kanıtıEPSS %5moodle · moodle18 May 2022
- CVE-2004-223341Planlayın
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2moodle · moodle31 Ara 2004
- CVE-2004-223741Planlayın
Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."
KritikCVSS 10,0İstismar yokEPSS %2moodle · moodle31 Ara 2004
- CVE-2020-1432140Planlayın
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
YüksekCVSS 8,8SilahlaştırılmışEPSS %16moodle · moodle16 Ağu 2022
- CVE-2021-394340Planlayın
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions.
KritikCVSS 9,8İstismar yokEPSS %2moodle · moodle22 Kas 2021
- CVE-2022-4031440Planlayın
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
KritikCVSS 9,8İstismar yokEPSS %2moodle · moodle30 Eyl 2022
- CVE-2005-224740Planlayın
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2moodle · moodle12 Tem 2005
- CVE-2006-493640Planlayın
Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and
KritikCVSS 10,0İstismar yokEPSS %1moodle · moodle22 Eyl 2006
- CVE-2006-493540Planlayın
The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.
KritikCVSS 10,0İstismar yokEPSS %1moodle · moodle22 Eyl 2006
- CVE-2004-223640Planlayın
Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.
KritikCVSS 10,0İstismar yokEPSS %1moodle · moodle31 Ara 2004
- CVE-2004-223540Planlayın
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
KritikCVSS 10,0İstismar yokEPSS %1moodle · moodle31 Ara 2004
- CVE-2019-380940Planlayın
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.
KritikCVSS 10,0İstismar yokEPSS %1moodle · moodle25 Mar 2019
- CVE-2022-3059939İzleyin
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
KritikCVSS 9,8İstismar yokEPSS %1moodle · moodle18 May 2022
- CVE-2023-555039İzleyin
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
KritikCVSS 9,8İstismar yokEPSS %1moodle · moodle9 Kas 2023
- CVE-2023-2833339İzleyin
Moodle: pix helper potential mustache code injection risk
KritikCVSS 9,8İstismar yokEPSS %1moodle · moodle23 Mar 2023
- CVE-2022-4031539İzleyin
A limited SQL injection risk was identified in the "browse list of users" site administration page.
KritikCVSS 9,8İstismar yokEPSS %1moodle · moodle30 Eyl 2022