Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
progress moveit transfer vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2023-36932
In Progress MOVEit Transfer prior to 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an auth...
Progress Moveit Transfer
1 Article
7.5
CVSSv3
CVE-2023-36933
In Progress MOVEit Transfer prior to 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an malicious user to invoke a method that results in an unhandled exception. Triggering this workflow can cause the MOVEit Tr...
Progress Moveit Transfer
1 Article
9.1
CVSSv3
CVE-2023-36934
In Progress MOVEit Transfer prior to 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticate...
Progress Moveit Transfer
1 Article
8.8
CVSSv3
CVE-2021-31827
In Progress MOVEit Transfer prior to 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated malicious user to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being ...
Progress Moveit Transfer
5.4
CVSSv3
CVE-2020-28647
In Progress MOVEit Transfer prior to 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim...
Progress Moveit Transfer
2 Github repositories
8.8
CVSSv3
CVE-2021-33894
In Progress MOVEit Transfer prior to 2019.0.6 (11.0.6), 2019.1.x prior to 2019.1.5 (11.1.5), 2019.2.x prior to 2019.2.2 (11.2.2), 2020.x prior to 2020.0.5 (12.0.5), 2020.1.x prior to 2020.1.4 (12.1.4), and 2021.x prior to 2021.0.1 (13.0.1), a SQL injection vulnerability exists in...
Progress Moveit Transfer
6.1
CVSSv3
CVE-2023-42656
In Progress MOVEit Transfer versions released prior to 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a maliciou...
Progress Moveit Transfer
8.8
CVSSv3
CVE-2023-42660
In Progress MOVEit Transfer versions released prior to 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated malicious user to gain ...
Progress Moveit Transfer
9.8
CVSSv3
CVE-2023-35708
In Progress MOVEit Transfer prior to 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated malicious user to g...
Progress Moveit Transfer
2 Github repositories
4 Articles
9.8
CVSSv3
CVE-2019-18465
In Progress MOVEit Transfer 11.1 prior to 11.1.3, a vulnerability has been found that could allow an malicious user to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the My...
Ipswitch Moveit Transfer
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »