Vulnerability index

Browse CVEs

383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2014-3552 The Shibboleth authentication plugin in auth/shibboleth/index.php in Moodle through 2.3.11, 2.4.x before 2.4.11, and 2.5.x before 2.5.7 does not chec… Moodle after 2.3.11 Fix from $1,6002014-07-29 MEDIUM 5.0 CVE-2014-3546 Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requir… Moodle after 2.3.11 Fix from $1,6002014-07-29 HIGH 7.5 CVE-2014-3541 The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remot… Moodle Patch available Fix from $1,9502014-07-29 MEDIUM 6.8 CVE-2014-0213 Multiple cross-site request forgery (CSRF) vulnerabilities in mod/assign/locallib.php in the Assignment subsystem in Moodle through 2.3.11, 2.4.x bef… Moodle after 2.3.11 Fix from $1,6002014-05-27 MEDIUM 6.8 CVE-2014-0214 login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token wi… Moodle after 2.3.11 Fix from $1,6002014-05-27 MEDIUM 5.0 CVE-2014-0216 The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2… Moodle after 2.3.11 Fix from $1,6002014-05-27 MEDIUM 6.8 CVE-2014-0126 Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5… Moodle after 2.3.11 Fix from $1,6002014-03-24 MEDIUM 5.8 CVE-2014-0125 repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, w… Moodle after 2.3.11 Fix from $1,6002014-03-24 MEDIUM 6.8 CVE-2014-0010 Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.… Moodle Patch available Fix from $1,6002014-01-20 MEDIUM 5.5 CVE-2014-0009 course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the… Moodle after 2.2.11 Fix from $1,6002014-01-20 MEDIUM 6.8 CVE-2013-4524 Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x befor… Moodle after 2.2.11 Fix from $1,6002013-11-26 MEDIUM 5.0 CVE-2013-4522 lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP… Moodle after 2.2.11 Fix from $1,6002013-11-26 HIGH 7.5 CVE-2013-4313 Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which… Moodle after 2.2.11 Fix from $1,9502013-09-16 HIGH 7.5 CVE-2013-5674 badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, whi… Moodle Patch available Fix from $1,9502013-09-16 MEDIUM 5.8 CVE-2012-6087 repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verif… Moodle after 2.2.11 Fix from $1,6002013-09-16 MEDIUM 5.0 CVE-2013-2082 Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comm… Moodle Patch available Fix from $1,6002013-05-25 MEDIUM 5.0 CVE-2013-2083 The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not prop… Moodle Patch available Fix from $1,6002013-05-25 MEDIUM 6.5 CVE-2013-1836 Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories… Moodle Mitigation only Fix from $1,6002013-03-25 MEDIUM 5.0 CVE-2013-1831 lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive… Moodle Patch available Fix from $1,6002013-03-25 MEDIUM 5.5 CVE-2012-6106 calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remot… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2012-6104 blog/rsslib.php in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allows remote attackers to obtain sensitive information from… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2012-6105 blog/rsslib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 continues to provide a blog RSS feed af… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2012-6112 classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.… Moodle Patch available Fix from $1,6002013-01-27 MEDIUM 6.8 CVE-2012-6103 Multiple cross-site request forgery (CSRF) vulnerabilities in user/messageselect.php in the messaging system in Moodle 2.2.x before 2.2.7, 2.3.x befo… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.4 CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to rea… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.8 CVE-2012-6101 Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect us… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 6.5 CVE-2012-5479 The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute… Moodle Mitigation only Fix from $1,6002012-11-21 MEDIUM 6.4 CVE-2012-5480 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest… Moodle Mitigation only Fix from $1,6002012-11-21 MEDIUM 6.5 CVE-2012-5471 The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to acce… Moodle Patch available Fix from $1,6002012-11-21 MEDIUM 5.5 CVE-2012-4408 course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, … Moodle Patch available Fix from $1,6002012-09-19