Vulnerabilities > Minitool

DATE CVE VULNERABILITY TITLE RISK
2023-09-19 CVE-2023-38351 Improper Certificate Validation vulnerability in Minitool Partition Wizard 12.8
MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
network
high complexity
minitool CWE-295
8.1
2023-09-19 CVE-2023-38352 Improper Certificate Validation vulnerability in Minitool Partition Wizard 12.8
MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.
network
high complexity
minitool CWE-295
8.1
2023-09-19 CVE-2023-38353 Improper Certificate Validation vulnerability in Minitool Power Data Recovery 11.5/11.6
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
network
high complexity
minitool CWE-295
5.9
2023-09-19 CVE-2023-38354 Improper Certificate Validation vulnerability in Minitool Shadowmaker 4.1
MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
network
high complexity
minitool CWE-295
8.1
2023-09-19 CVE-2023-38355 Improper Certificate Validation vulnerability in Minitool Movie Maker 7.0
MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
network
high complexity
minitool CWE-295
8.1
2023-09-19 CVE-2023-38356 Improper Certificate Validation vulnerability in Minitool Power Data Recovery 11.6
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
network
high complexity
minitool CWE-295
8.1
2022-05-20 CVE-2022-29320 Unquoted Search Path or Element vulnerability in Minitool Partition Wizard 12.0
MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.
local
low complexity
minitool CWE-428
7.2