Known vulnerabilities in Moodle - page 21

Vendor: moodle.org
Software: Moodle
Software CPE: cpe:2.3:a:moodle_org:moodle:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 605
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Moodle Moodle is affected by 605 known vulnerabilities: 28 high, 241 medium, 335 low Critical High Medium Low

Vulnerabilities (605)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU40472 - Permissions, Privileges, and Access Controls
CVE-2015-3273
CWE-264 Low
No
No
- 22.02.2016 SB2016022210
SB2015090307
SB2015090308
and 1 more
#VU40473 - Improper input validation
CVE-2015-3272
CWE-20 Medium
No
No
- 22.02.2016 SB2016022210
SB2015090307
SB2015090308
and 1 more
#VU40730 - Permissions, Privileges, and Access Controls
CVE-2015-3181
CWE-264 Low
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40731 - Permissions, Privileges, and Access Controls
CVE-2015-3179
CWE-264 Low
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40732 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3180
CWE-200 Low
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40733 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-3178
CWE-79 Low
No
No
2.6.11, 2.7.8, 2.8.6 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40734 - Improper input validation
CVE-2015-3177
CWE-20 Low
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40735 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3176
CWE-200 Medium
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40736 - Improper input validation
CVE-2015-3175
CWE-20 Medium
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40737 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-3174
CWE-79 Low
No
No
- 01.06.2015 SB2015060101
SB2015090307
SB2015090308
and 1 more
#VU40738 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-2273
CWE-79 Low
No
No
2.6.9, 2.7.6, 2.8.4 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40739 - Permissions, Privileges, and Access Controls
CVE-2015-2272
CWE-264 Low
No
No
- 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40740 - Permissions, Privileges, and Access Controls
CVE-2015-2271
CWE-264 Low
No
No
- 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40741 - Improper input validation
CVE-2015-2270
CWE-20 Medium
No
No
- 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40742 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-2269
CWE-79 Low
Available
No
2.6.9, 2.7.6, 2.8.4 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40743 - Resource Management Errors
CVE-2015-2268
CWE-399 Low
No
No
- 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40744 - Improper Access Control
CVE-2015-2267
CWE-284 Low
No
No
- 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40745 - Exposure of sensitive information to an unauthorized actor
CVE-2015-2266
CWE-200 Low
No
No
- 01.06.2015 SB2015060102
SB2015032407
SB2015032408
and 1 more
#VU40746 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2015-1493
CWE-22 Medium
No
No
2.6.8, 2.7.5, 2.8.3 01.06.2015 SB2015060103
SB2015032407
SB2015032408
and 1 more
#VU40749 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2015-0216
CWE-79 Low
No
No
- 01.06.2015 SB2015060105
SB2015020501
SB2015020502


Showing elements 401 - 420 out of 605