Vulnerabilities > Minitool > Power Data Recovery > 11.6

DATE CVE VULNERABILITY TITLE RISK
2023-09-19 CVE-2023-38353 Improper Certificate Validation vulnerability in Minitool Power Data Recovery 11.5/11.6
MiniTool Power Data Recovery version 11.6 and before contains an insecure in-app payment system that allows attackers to steal highly sensitive information through a man in the middle attack.
network
high complexity
minitool CWE-295
5.9
2023-09-19 CVE-2023-38356 Improper Certificate Validation vulnerability in Minitool Power Data Recovery 11.6
MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.
network
high complexity
minitool CWE-295
8.1