Known vulnerabilities in Moodle - page 18

Vendor: moodle.org
Software: Moodle
Software CPE: cpe:2.3:a:moodle_org:moodle:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 605
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Moodle Moodle is affected by 605 known vulnerabilities: 28 high, 241 medium, 335 low Critical High Medium Low

Vulnerabilities (605)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU37616 - Server-Side Request Forgery (SSRF)
CVE-2018-1042
CWE-918 Medium
Available
No
- 22.01.2018 SB2018012214
SB2018012331
SB2018012332
and 1 more
#VU37617 - Improper input validation
CVE-2018-1043
CWE-20 Medium
No
No
- 22.01.2018 SB2018012214
SB2018012331
SB2018012332
and 1 more
#VU37618 - Exposure of sensitive information to an unauthorized actor
CVE-2018-1044
CWE-200 Low
No
No
- 22.01.2018 SB2018012214
SB2018012331
SB2018012332
and 1 more
#VU37619 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-1045
CWE-79 Low
No
No
- 22.01.2018 SB2018012215
SB2018012331
SB2018012332
and 1 more
#VU38275 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-12156
CWE-79 Low
No
No
- 18.09.2017 SB2017091819
SB2017092027
SB2017092028
and 1 more
#VU38276 - Exposure of sensitive information to an unauthorized actor
CVE-2017-12157
CWE-200 Low
No
No
- 18.09.2017 SB2017071726
SB2017092027
SB2017092028
and 1 more
#VU38684 - Exposure of sensitive information to an unauthorized actor
CVE-2017-2642
CWE-200 Medium
No
No
- 17.07.2017 SB2017071726
SB2017072037
SB2017072038
and 2 more
#VU38685 - Exposure of sensitive information to an unauthorized actor
CVE-2017-7531
CWE-200 Low
No
No
- 17.07.2017 SB2017071728
#VU38686 - Improper Privilege Management
CVE-2017-7532
CWE-269 Medium
No
No
- 17.07.2017 SB2017071726
SB2017072037
SB2017072038
and 2 more
#VU38992 - Improper Privilege Management
CVE-2017-7489
CWE-269 Medium
No
No
- 15.05.2017 SB2017032915
SB2017051709
SB2017051710
and 2 more
#VU38993 - Improper input validation
CVE-2017-7490
CWE-20 Medium
No
No
- 15.05.2017 SB2017032915
SB2017051709
SB2017051710
and 2 more
#VU38994 - Cross-Site Request Forgery (CSRF)
CVE-2017-7491
CWE-352 Low
No
No
- 15.05.2017 SB2017032915
SB2017051709
SB2017051710
and 2 more
#VU39158 - Improper Access Control
CVE-2016-3729
CWE-284 Medium
No
No
- 21.04.2017 SB2017042106
SB2016050947
SB2016050948
and 1 more
#VU39159 - Exposure of sensitive information to an unauthorized actor
CVE-2016-3731
CWE-200 Medium
No
No
- 21.04.2017 SB2017042106
SB2016050947
SB2016050948
and 1 more
#VU39160 - Exposure of sensitive information to an unauthorized actor
CVE-2016-3732
CWE-200 Low
No
No
- 21.04.2017 SB2017042106
SB2016050947
SB2016050948
and 1 more
#VU39161 - Improper Access Control
CVE-2016-3733
CWE-284 Low
No
No
- 21.04.2017 SB2017042106
SB2016050947
SB2016050948
and 1 more
#VU39162 - Cross-Site Request Forgery (CSRF)
CVE-2016-3734
CWE-352 High
No
No
- 21.04.2017 SB2017042106
SB2016050947
SB2016050948
and 1 more
#VU39346 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-7298
CWE-79 Low
No
No
- 29.03.2017 SB2017032915
#VU39375 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2017-2641
CWE-89 High
Available
No
- 26.03.2017 SB2017032603
SB2017031307
SB20170314171
and 3 more
#VU39376 - Exposure of sensitive information to an unauthorized actor
CVE-2017-2643
CWE-200 Medium
No
No
- 26.03.2017 SB2017032603
SB2017031307
SB20170314171
and 3 more


Showing elements 341 - 360 out of 605