Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 647

Количество 2 647

ubuntu логотип

CVE-2025-62401

4 месяца назад

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-62401

4 месяца назад

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-62401

4 месяца назад

An issue in Moodle\u2019s timed assignment feature allowed students to ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-62400

4 месяца назад

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-62400

4 месяца назад

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2025-62400

4 месяца назад

Moodle exposed the names of hidden groups to users who had permission ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2025-62399

4 месяца назад

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-62399

4 месяца назад

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-62399

4 месяца назад

Moodle\u2019s mobile and web service authentication endpoints did not ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-62398

4 месяца назад

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-62398

4 месяца назад

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-62398

4 месяца назад

A serious authentication flaw allowed attackers with valid credentials ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-62397

4 месяца назад

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-62397

4 месяца назад

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-62397

4 месяца назад

The router\u2019s inconsistent response to invalid course IDs allowed ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-62396

4 месяца назад

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-62396

4 месяца назад

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-62396

4 месяца назад

An error-handling issue in the Moodle router (r.php) could cause the a ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-62395

4 месяца назад

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2025-62395

4 месяца назад

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-62401

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

CVSS3: 5.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62401

An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them more time than allowed to complete an assessment.

CVSS3: 5.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-62401

An issue in Moodle\u2019s timed assignment feature allowed students to ...

CVSS3: 5.4
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

CVSS3: 4.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden groups. This could reveal private or restricted group information.

CVSS3: 4.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-62400

Moodle exposed the names of hidden groups to users who had permission ...

CVSS3: 4.3
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-62399

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62399

Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, making them susceptible to brute-force attacks.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-62399

Moodle\u2019s mobile and web service authentication endpoints did not ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-62398

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

CVSS3: 5.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62398

A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certain conditions, potentially compromising user accounts.

CVSS3: 5.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-62398

A serious authentication flaw allowed attackers with valid credentials ...

CVSS3: 5.4
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-62397

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

CVSS3: 5.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62397

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially aiding reconnaissance.

CVSS3: 5.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-62397

The router\u2019s inconsistent response to invalid course IDs allowed ...

CVSS3: 5.3
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-62396

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS3: 5.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62396

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS3: 5.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-62396

An error-handling issue in the Moodle router (r.php) could cause the a ...

CVSS3: 5.3
0%
Низкий
4 месяца назад
ubuntu логотип
CVE-2025-62395

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-62395

A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information from the system context, revealing restricted administrative data.

CVSS3: 4.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу