Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
moveit transfer vulnerabilities and exploits
(subscribe to this query)
7.1
CVSSv3
CVE-2024-0396
In Progress MOVEit Transfer versions released prior to 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue exists. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead ...
Progress Moveit Transfer
6.1
CVSSv3
CVE-2023-6217
In Progress MOVEit Transfer versions released prior to 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer. An attacker could craft a m...
Progress Moveit Transfer
6.1
CVSSv3
CVE-2023-42656
In Progress MOVEit Transfer versions released prior to 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a maliciou...
Progress Moveit Transfer
5.4
CVSSv3
CVE-2020-28647
In Progress MOVEit Transfer prior to 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Transfer instance interacts with the stored payload, it could invoke and execute arbitrary code within the context of the victim...
Progress Moveit Transfer
2 Github repositories
5.4
CVSSv3
CVE-2015-7676
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and previous versions, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.
Ipswitch Moveit Dmz
NA
CVE-2024-2291
In Progress MOVEit Transfer versions released prior to 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the ...
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3