First CVE: Sep 14, 2017Active for: 9 years
303
CVEs Published
More CVEs Published than 83% of tracked CNAs
33.7
Avg CVEs / Year
More Avg CVEs / Year than 78% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 31% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by [email protected] over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2017
8 years ago
Most Recent CVE
Jul 16, 2026
8 days ago
Top CVEs
All CVEs published by [email protected] as a CNA, regardless of affected vendor or product.
303 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43425HIGH A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/updat | Nov 7, 2024 | 8.1 | 90 | NO | YES |
CVE-2021-36393CRITICAL In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses. | Mar 6, 2023 | 9.8 | 60 | NO | NO |
CVE-2022-0332CRITICAL A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data. | Jan 25, 2022 | 9.8 | 59 | NO | YES |
CVE-2022-35650HIGH The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This | Jul 25, 2022 | 7.5 | 50 | NO | NO |
CVE-2025-12744HIGH A flaw was found in the ABRT daemon’s handling of user-supplied mount information.ABRT copies up to 12 characters from an untrusted input and places them directly into a shell comm | Dec 3, 2025 | 8.8 | 42 | NO | YES |
CVE-2022-35649CRITICAL The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk | Jul 25, 2022 | 9.8 | 34 | NO | NO |
CVE-2025-69194CRITICAL A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink <file name> elements. An a | Jan 9, 2026 | 9.8 | 33 | NO | NO |
CVE-2021-36394CRITICAL In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | Mar 6, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-35653MEDIUM A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attack | Jul 25, 2022 | 6.1 | 33 | NO | YES |
CVE-2022-30600CRITICAL A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed. | May 18, 2022 | 9.8 | 33 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA303 CVEs
53%
36%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local70 (23.1%)
Network231 (76.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (0.7%)
Attack Complexity
Low285 (94.1%)
High18 (5.9%)
Unknown0 (0.0%)
User Interaction
None199 (65.7%)
Unknown0 (0.0%)
Required104 (34.3%)
Privileges Required
Low86 (28.4%)
High14 (4.6%)
None203 (67.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (303 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.3% of CVEs· 80th percentile
Nuclei
3 CVEs
1.0% of CVEs· 80th percentile
ExploitDB
3 CVEs
1.0% of CVEs· 82nd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by [email protected] as a CNA.
Media Mentions
Media articles that mention a CVE ID published by [email protected] as a CNA — matched by CVE ID, not by organization name.