Записи Moodle
631 опубликованных записей вендора moodle.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 5 · 0,8 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 74,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')134
- CWE-264 Permissions, Privileges, and Access Controls88
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor85
- CWE-352 Cross-Site Request Forgery (CSRF)35
- CWE-20 Improper Input Validation28
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')25
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
631 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2024-43425Готовый эксплойт | Moodle: remote code execution via calculated question typesmoodle · moodle · CWE-94 | Высокая8,1 | — | 87,5 % | 7 нояб. 2024 г. |
55В плане | CVE-2021-36393Proof of concept | In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.moodle · moodle · CWE-89 | Критическая9,8 | — | 52,3 % | 6 мар. 2023 г. |
52В плане | CVE-2022-0332Proof of concept | A flaw was found in Moodle in versions 3.11 to 3.11.4.moodle · moodle · CWE-89 | Критическая9,8 | — | 44,9 % | 25 янв. 2022 г. |
45В плане | CVE-2022-35650Proof of concept | The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions.moodle · moodle · CWE-22 | Высокая7,5 | — | 49,1 % | 25 июл. 2022 г. |
45В плане | CVE-2018-1133Proof of concept | An issue was discovered in Moodle 3.x.moodle · moodle · CWE-94 | Высокая8,8 | — | 31,9 % | 25 мая 2018 г. |
43В плане | CVE-2021-21809Готовый эксплойт | A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10.moodle · moodle · CWE-78 | Критическая9,1 | — | 24,2 % | 23 июн. 2021 г. |
43В плане | CVE-2017-2641Proof of concept | In Moodle 2.x and 3.x, SQL injection can occur via user preferences.moodle · moodle · CWE-89 | Критическая9,8 | — | 14,5 % | 26 мар. 2017 г. |
42В плане | CVE-2022-35649Proof of concept | The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code.moodle · moodle · CWE-94 | Критическая9,8 | — | 8,7 % | 25 июл. 2022 г. |
41В плане | CVE-2021-36394Proof of concept | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.moodle · moodle · CWE-384 | Критическая9,8 | — | 7,0 % | 6 мар. 2023 г. |
41В плане | CVE-2022-30600Proof of concept | A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.moodle · moodle · CWE-682 | Критическая9,8 | — | 5,1 % | 18 мая 2022 г. |
41В плане | CVE-2004-2233Эксплойта нет | Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.moodle · moodle | Критическая10,0 | — | 1,7 % | 31 дек. 2004 г. |
41В плане | CVE-2004-2237Эксплойта нет | Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."moodle · moodle | Критическая10,0 | — | 1,7 % | 31 дек. 2004 г. |
40В плане | CVE-2020-14321Готовый эксплойт | In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.moodle · moodle · CWE-863 | Высокая8,8 | — | 16,2 % | 16 авг. 2022 г. |
40В плане | CVE-2021-3943Эксплойта нет | A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions.moodle · moodle · CWE-20 | Критическая9,8 | — | 2,5 % | 22 нояб. 2021 г. |
40В плане | CVE-2022-40314Эксплойта нет | A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.moodle · moodle · CWE-502 | Критическая9,8 | — | 2,0 % | 30 сент. 2022 г. |
40В плане | CVE-2005-2247Эксплойта нет | Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.moodle · moodle | Критическая10,0 | — | 1,5 % | 12 июл. 2005 г. |
40В плане | CVE-2006-4936Эксплойта нет | Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact andmoodle · moodle · CWE-20 | Критическая10,0 | — | 1,5 % | 22 сент. 2006 г. |
40В плане | CVE-2006-4935Эксплойта нет | The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.moodle · moodle · CWE-20 | Критическая10,0 | — | 1,5 % | 22 сент. 2006 г. |
40В плане | CVE-2004-2236Эксплойта нет | Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.moodle · moodle | Критическая10,0 | — | 1,4 % | 31 дек. 2004 г. |
40В плане | CVE-2004-2235Эксплойта нет | Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.moodle · moodle | Критическая10,0 | — | 1,4 % | 31 дек. 2004 г. |
40В плане | CVE-2019-3809Эксплойта нет | A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.moodle · moodle · CWE-352 | Критическая10,0 | — | 0,9 % | 25 мар. 2019 г. |
39Наблюдать | CVE-2022-30599Эксплойта нет | A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.moodle · moodle · CWE-89 | Критическая9,8 | — | 1,4 % | 18 мая 2022 г. |
39Наблюдать | CVE-2023-5550Эксплойта нет | Moodle: rce due to lfi risk in some misconfigured shared hosting environmentsmoodle · moodle · CWE-94 | Критическая9,8 | — | 1,4 % | 9 нояб. 2023 г. |
39Наблюдать | CVE-2023-28333Эксплойта нет | Moodle: pix helper potential mustache code injection riskmoodle · moodle · CWE-94 | Критическая9,8 | — | 1,2 % | 23 мар. 2023 г. |
39Наблюдать | CVE-2022-40315Эксплойта нет | A limited SQL injection risk was identified in the "browse list of users" site administration page.moodle · moodle · CWE-89 | Критическая9,8 | — | 1,0 % | 30 сент. 2022 г. |
- CVE-2024-4342558В плане
Moodle: remote code execution via calculated question types
ВысокаяCVSS 8,1Готовый эксплойтEPSS 88 %moodle · moodle7 нояб. 2024 г.
- CVE-2021-3639355В плане
In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.
КритическаяCVSS 9,8Proof of conceptEPSS 52 %moodle · moodle6 мар. 2023 г.
- CVE-2022-033252В плане
A flaw was found in Moodle in versions 3.11 to 3.11.4.
КритическаяCVSS 9,8Proof of conceptEPSS 45 %moodle · moodle25 янв. 2022 г.
- CVE-2022-3565045В плане
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions.
ВысокаяCVSS 7,5Proof of conceptEPSS 49 %moodle · moodle25 июл. 2022 г.
- CVE-2018-113345В плане
An issue was discovered in Moodle 3.x.
ВысокаяCVSS 8,8Proof of conceptEPSS 32 %moodle · moodle25 мая 2018 г.
- CVE-2021-2180943В плане
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10.
КритическаяCVSS 9,1Готовый эксплойтEPSS 24 %moodle · moodle23 июн. 2021 г.
- CVE-2017-264143В плане
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
КритическаяCVSS 9,8Proof of conceptEPSS 15 %moodle · moodle26 мар. 2017 г.
- CVE-2022-3564942В плане
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code.
КритическаяCVSS 9,8Proof of conceptEPSS 9 %moodle · moodle25 июл. 2022 г.
- CVE-2021-3639441В плане
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
КритическаяCVSS 9,8Proof of conceptEPSS 7 %moodle · moodle6 мар. 2023 г.
- CVE-2022-3060041В плане
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
КритическаяCVSS 9,8Proof of conceptEPSS 5 %moodle · moodle18 мая 2022 г.
- CVE-2004-223341В плане
Unknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %moodle · moodle31 дек. 2004 г.
- CVE-2004-223741В плане
Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %moodle · moodle31 дек. 2004 г.
- CVE-2020-1432140В плане
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.
ВысокаяCVSS 8,8Готовый эксплойтEPSS 16 %moodle · moodle16 авг. 2022 г.
- CVE-2021-394340В плане
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %moodle · moodle22 нояб. 2021 г.
- CVE-2022-4031440В плане
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %moodle · moodle30 сент. 2022 г.
- CVE-2005-224740В плане
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %moodle · moodle12 июл. 2005 г.
- CVE-2006-493640В плане
Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %moodle · moodle22 сент. 2006 г.
- CVE-2006-493540В плане
The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %moodle · moodle22 сент. 2006 г.
- CVE-2004-223640В плане
Unknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %moodle · moodle31 дек. 2004 г.
- CVE-2004-223540В плане
Unknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %moodle · moodle31 дек. 2004 г.
- CVE-2019-380940В плане
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %moodle · moodle25 мар. 2019 г.
- CVE-2022-3059939Наблюдать
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moodle · moodle18 мая 2022 г.
- CVE-2023-555039Наблюдать
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moodle · moodle9 нояб. 2023 г.
- CVE-2023-2833339Наблюдать
Moodle: pix helper potential mustache code injection risk
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moodle · moodle23 мар. 2023 г.
- CVE-2022-4031539Наблюдать
A limited SQL injection risk was identified in the "browse list of users" site administration page.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %moodle · moodle30 сент. 2022 г.