Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.33% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.37% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.37% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.60% | — | Progress Moveit Transfer | 23/7/2026 | 30/7/2026 | Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3. | |
| Analizada | Crítica (9.8) | 0.55% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. | |
| Analizada | Alta (8.8) | 0.37% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Alta (7.5) | 0.37% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Alta (7.5) | 0.60% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Crítica (9.8) | 0.46% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Media (5.4) | 0.41% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |
| Analizada | Alta (7.2) | 0.64% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |
| Analizada | Alta (7.5) | 0.21% | — | Progress Moveit Transfer | 7/1/2026 | 17/6/2026 | Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10. | |
| Analizada | Media (5.3) | 0.27% | — | Progress Moveit Transfer | 19/11/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4. | |
| Aplazada | Alta (8.2) | 0.48% | — | Progress Moveit TransferAI | 29/10/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Progress MOVEit Transfer (AS2 module).This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.3, from 2024.1.0 before 2024.1.7, from 2023.1.0 before 2023.1.16. | |
| Analizada | Alta (8.8) | 0.26% | — | Progress Moveit Transfer | 19/3/2025 | 17/6/2026 | Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before 2024.1.2. | |
| Analizada | Crítica (9.8) | 0.62% | — | Progress Moveit Transfer | 29/7/2024 | 17/6/2026 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3. | |
| Analizada | Crítica (9.8) | 81% | — | Progress Moveit Transfer | 25/6/2024 | 17/6/2026 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2. | |
| Analizada | Media (4.3) | 0.39% | — | Progress Moveit Transfer | 20/3/2024 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user… | |
| Modificada | Alta (7.1) | 0.54% | — | Progress Moveit Transfer | 17/1/2024 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction could lead to computational errors within… | |
| Modificada | Alta (7.2) | 0.70% | — | Progress Moveit Transfer | 29/11/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified. It is possible for a group administrator to elevate a group members permissions to the role of an organization… | |
| Modificada | Media (6.1) | 0.51% | — | Progress Moveit Transfer | 29/11/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer. An attacker could craft a malicious payload targeting the system… | |
| Modificada | Alta (8.8) | 0.70% | — | Progress Moveit Transfer | 20/9/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer… | |
| Modificada | Media (6.1) | 0.55% | — | Progress Moveit Transfer | 20/9/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface. An attacker could craft a malicious payload targeting MOVEit Transfer users… | |
| Modificada | Alta (7.2) | 0.68% | — | Progress Moveit Transfer | 20/9/2023 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to gain unauthorized access to the MOVEit… |