Latest CVE Feed
-
5.3
MEDIUMCVE-2012-1169
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.... Read more
- EPSS Score: %0.99
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2012-1168
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.... Read more
- EPSS Score: %2.22
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1161
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results... Read more
- EPSS Score: %0.95
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-1160
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php... Read more
- EPSS Score: %0.75
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1159
Moodle before 2.2.2: Overview report allows users to see hidden courses... Read more
- EPSS Score: %0.95
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1158
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export... Read more
- EPSS Score: %0.95
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1157
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default... Read more
- EPSS Score: %0.58
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %1.23
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-1155
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to... Read more
- EPSS Score: %1.27
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-1124
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.... Read more
Affected Products : phxeventmanager- EPSS Score: %2.92
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-1115
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.... Read more
- EPSS Score: %0.84
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2012-1114
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.... Read more
- EPSS Score: %0.84
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-1109
mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions... Read more
Affected Products : mwlib- EPSS Score: %0.68
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-1105
An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.... Read more
- EPSS Score: %0.15
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2012-1104
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.... Read more
- EPSS Score: %0.24
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-1102
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the... Read more
Affected Products : \- EPSS Score: %0.29
- Published: Jul. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-1101
systemd 37-1 does not properly handle non-existent services, which causes a denial of service (failure of login procedure).... Read more
Affected Products : systemd- EPSS Score: %0.15
- Published: Mar. 11, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2012-1096
NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection.... Read more
- EPSS Score: %0.35
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2012-1094
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.... Read more
- EPSS Score: %0.24
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2012-1093
The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation.... Read more
- EPSS Score: %0.14
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024