📦 Moveit Transfer

by Progress

🔍 What is Moveit Transfer?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-36934

CRITICAL CVSS 9.1 Jul 5, 2023

This is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated attackers to access and modify the database. All organizations running affected versions of MOVEi...

CVE-2023-35708

CRITICAL CVSS 9.8 Jun 16, 2023

This is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated attackers to execute arbitrary SQL commands against the application's database. Attackers can mod...

CVE-2023-35036

CRITICAL CVSS 9.1 Jun 12, 2023

CVE-2023-35036 is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated attackers to execute arbitrary SQL commands against the database. This can lead to data...

CVE-2021-38159

CRITICAL CVSS 9.8 Aug 7, 2021

CVE-2021-38159 is a critical SQL injection vulnerability in Progress MOVEit Transfer that allows unauthenticated remote attackers to execute arbitrary SQL commands against the database. This could lea...

CVE-2024-0396

HIGH CVSS 7.1 Jan 17, 2024

This CVE describes an input validation vulnerability in Progress MOVEit Transfer that allows authenticated users to manipulate HTTPS transaction parameters. Successful exploitation could cause computa...

CVE-2023-6217

HIGH CVSS 7.1 Nov 29, 2023

This reflected cross-site scripting (XSS) vulnerability in Progress MOVEit Transfer allows attackers to execute malicious JavaScript in victims' browsers when MOVEit Gateway is deployed with MOVEit Tr...

CVE-2023-42660

HIGH CVSS 8.8 Sep 20, 2023

This SQL injection vulnerability in Progress MOVEit Transfer allows authenticated attackers to execute arbitrary SQL commands against the database. Attackers could read, modify, or delete sensitive da...

CVE-2023-36932

HIGH CVSS 8.1 Jul 5, 2023

This CVE describes multiple SQL injection vulnerabilities in Progress MOVEit Transfer that allow authenticated attackers to modify and disclose database content. Organizations using affected versions ...

CVE-2021-37614

HIGH CVSS 8.8 Aug 5, 2021

This SQL injection vulnerability in Progress MOVEit Transfer allows authenticated remote attackers to execute arbitrary SQL queries against the database. Attackers can read, modify, or delete database...

CVE-2021-33894

HIGH CVSS 8.8 Jun 9, 2021

This SQL injection vulnerability in Progress MOVEit Transfer allows authenticated attackers to execute arbitrary SQL commands against the database. Affected organizations using vulnerable versions cou...

CVE-2025-13147

MEDIUM CVSS 5.3 Nov 19, 2025

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer that allows attackers to make unauthorized requests from the vulnerable server to internal or external...

CVE-2025-11235

LOW CVSS 3.7 Jan 7, 2026

This vulnerability allows attackers to change passwords without proper verification in Progress MOVEit Transfer's REST API modules on Windows. It affects organizations using vulnerable versions of MOV...