Перейти к содержимому
Noroxi

Записи Moodle

631 опубликованных записей вендора moodle.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
5 · 0,8 %
Pre-auth RCE
26
С записью об исправлении
74,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

631 записей
  • CVE-2024-43425
    58В плане

    Moodle: remote code execution via calculated question types

    ВысокаяCVSS 8,1Готовый эксплойтEPSS 88 %

    moodle · moodle7 нояб. 2024 г.

  • CVE-2021-36393
    55В плане

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

    КритическаяCVSS 9,8Proof of conceptEPSS 52 %

    moodle · moodle6 мар. 2023 г.

  • CVE-2022-0332
    52В плане

    A flaw was found in Moodle in versions 3.11 to 3.11.4.

    КритическаяCVSS 9,8Proof of conceptEPSS 45 %

    moodle · moodle25 янв. 2022 г.

  • CVE-2022-35650
    45В плане

    The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions.

    ВысокаяCVSS 7,5Proof of conceptEPSS 49 %

    moodle · moodle25 июл. 2022 г.

  • CVE-2018-1133
    45В плане

    An issue was discovered in Moodle 3.x.

    ВысокаяCVSS 8,8Proof of conceptEPSS 32 %

    moodle · moodle25 мая 2018 г.

  • CVE-2021-21809
    43В плане

    A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10.

    КритическаяCVSS 9,1Готовый эксплойтEPSS 24 %

    moodle · moodle23 июн. 2021 г.

  • CVE-2017-2641
    43В плане

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

    КритическаяCVSS 9,8Proof of conceptEPSS 15 %

    moodle · moodle26 мар. 2017 г.

  • CVE-2022-35649
    42В плане

    The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code.

    КритическаяCVSS 9,8Proof of conceptEPSS 9 %

    moodle · moodle25 июл. 2022 г.

  • CVE-2021-36394
    41В плане

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    moodle · moodle6 мар. 2023 г.

  • CVE-2022-30600
    41В плане

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    moodle · moodle18 мая 2022 г.

  • CVE-2004-2233
    41В плане

    Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    moodle · moodle31 дек. 2004 г.

  • CVE-2004-2237
    41В плане

    Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    moodle · moodle31 дек. 2004 г.

  • CVE-2020-14321
    40В плане

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 16 %

    moodle · moodle16 авг. 2022 г.

  • CVE-2021-3943
    40В плане

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    moodle · moodle22 нояб. 2021 г.

  • CVE-2022-40314
    40В плане

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    moodle · moodle30 сент. 2022 г.

  • CVE-2005-2247
    40В плане

    Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    moodle · moodle12 июл. 2005 г.

  • CVE-2006-4936
    40В плане

    Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    moodle · moodle22 сент. 2006 г.

  • CVE-2006-4935
    40В плане

    The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    moodle · moodle22 сент. 2006 г.

  • CVE-2004-2236
    40В плане

    Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    moodle · moodle31 дек. 2004 г.

  • CVE-2004-2235
    40В плане

    Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    moodle · moodle31 дек. 2004 г.

  • CVE-2019-3809
    40В плане

    A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    moodle · moodle25 мар. 2019 г.

  • CVE-2022-30599
    39Наблюдать

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    moodle · moodle18 мая 2022 г.

  • CVE-2023-5550
    39Наблюдать

    Moodle: rce due to lfi risk in some misconfigured shared hosting environments

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    moodle · moodle9 нояб. 2023 г.

  • CVE-2023-28333
    39Наблюдать

    Moodle: pix helper potential mustache code injection risk

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    moodle · moodle23 мар. 2023 г.

  • CVE-2022-40315
    39Наблюдать

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    moodle · moodle30 сент. 2022 г.