Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moveit vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2023-6218
In Progress MOVEit Transfer versions released prior to 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions...
Progress Moveit Transfer
9.8
CVSSv3
CVE-2019-18465
In Progress MOVEit Transfer 11.1 prior to 11.1.3, a vulnerability has been found that could allow an malicious user to sign in without full credentials via the SSH (SFTP) interface. The vulnerability affects only certain SSH (SFTP) configurations, and is applicable only if the My...
Ipswitch Moveit Transfer
9.1
CVSSv3
CVE-2023-35036
In Progress MOVEit Transfer prior to 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated malicious user to gain ...
Progress Moveit Transfer
5 Articles
7.1
CVSSv3
CVE-2024-0396
In Progress MOVEit Transfer versions released prior to 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue exists. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead ...
Progress Moveit Transfer
7.2
CVSSv3
CVE-2023-40043
In Progress MOVEit Transfer versions released prior to 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gai...
Progress Moveit Transfer
6.1
CVSSv3
CVE-2023-42656
In Progress MOVEit Transfer versions released prior to 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a maliciou...
Progress Moveit Transfer
6.1
CVSSv3
CVE-2020-12677
An issue exists in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated malicious user to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0 b...
Progress Moveit Automation
8.8
CVSSv3
CVE-2021-33894
In Progress MOVEit Transfer prior to 2019.0.6 (11.0.6), 2019.1.x prior to 2019.1.5 (11.1.5), 2019.2.x prior to 2019.2.2 (11.2.2), 2020.x prior to 2020.0.5 (12.0.5), 2020.1.x prior to 2020.1.4 (12.1.4), and 2021.x prior to 2021.0.1 (13.0.1), a SQL injection vulnerability exists in...
Progress Moveit Transfer
9.8
CVSSv3
CVE-2021-38159
In certain Progress MOVEit Transfer versions prior to 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote malicious user to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL...
Progress Moveit Transfer
5.4
CVSSv3
CVE-2020-28647
In Progress MOVEit Transfer prior to 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim...
Progress Moveit Transfer
2 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »