Логотип exploitDog
product: "moodle"
Консоль
Логотип exploitDog

exploitDog

product: "moodle"

Количество 2 643

Количество 2 643

debian логотип

CVE-2024-43439

около 1 года назад

A flaw was found in moodle. H5P error messages require additional sani ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-43438

около 1 года назад

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-43438

около 1 года назад

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-43438

около 1 года назад

A flaw was found in Feedback. Bulk messaging in the activity's non-res ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-43437

около 1 года назад

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-43437

около 1 года назад

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-43437

около 1 года назад

A flaw was found in moodle. Insufficient sanitizing of data when perfo ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2024-43436

около 1 года назад

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2024-43436

около 1 года назад

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

CVSS3: 7.2
EPSS: Низкий
debian логотип

CVE-2024-43436

около 1 года назад

A SQL injection risk flaw was found in the XMLDB editor tool available ...

CVSS3: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2024-43435

около 1 года назад

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-43435

около 1 года назад

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-43435

около 1 года назад

A flaw was found in moodle. Insufficient capability checks make it pos ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-43434

около 1 года назад

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-43434

около 1 года назад

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2024-43434

около 1 года назад

The bulk message sending feature in Moodle's Feedback module's non-res ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2024-43433

около 1 года назад

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-43433

около 1 года назад

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-43433

около 1 года назад

A flaw was found in moodle. Matrix room membership and power levels ar ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2024-43432

около 1 года назад

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2024-43439

A flaw was found in moodle. H5P error messages require additional sani ...

CVSS3: 5.4
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43438

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-43438

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.

CVSS3: 7.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-43438

A flaw was found in Feedback. Bulk messaging in the activity's non-res ...

CVSS3: 7.5
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43437

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

CVSS3: 5.4
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-43437

A flaw was found in moodle. Insufficient sanitizing of data when performing a restore could result in a cross-site scripting (XSS) risk from malicious backup files.

CVSS3: 5.4
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-43437

A flaw was found in moodle. Insufficient sanitizing of data when perfo ...

CVSS3: 5.4
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43436

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

CVSS3: 7.2
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-43436

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

CVSS3: 7.2
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-43436

A SQL injection risk flaw was found in the XMLDB editor tool available ...

CVSS3: 7.2
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43435

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

CVSS3: 5.3
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-43435

A flaw was found in moodle. Insufficient capability checks make it possible for users with access to restore glossaries in courses to restore them into the global site glossary.

CVSS3: 5.3
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-43435

A flaw was found in moodle. Insufficient capability checks make it pos ...

CVSS3: 5.3
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

CVSS3: 8.1
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

CVSS3: 8.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-43434

The bulk message sending feature in Moodle's Feedback module's non-res ...

CVSS3: 8.1
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS3: 5.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels are incorrectly applied and revoked for suspended Moodle users.

CVSS3: 5.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-43433

A flaw was found in moodle. Matrix room membership and power levels ar ...

CVSS3: 5.3
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-43432

A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

CVSS3: 5.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу