vciy

CVEs we hold for Progress

Records whose assigning authority named Progress as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9272Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADSProgress Software Flowmon ADS
CVE-2026-9203Server-side request forgery in Progress MarkLogic ServerProgress Software Corporation MarkLogic Server
CVE-2026-9195Cross-site scripting in Progress MarkLogic Server Query ConsoleProgress Software Corporation MarkLogic Server
CVE-2026-9193Privilege escalation in Progress MarkLogic Server Hadoop integrationProgress Software Corporation MarkLogic Server
CVE-2026-9192Authentication bypass in Progress MarkLogic Server ODBC App ServerProgress Software Corporation MarkLogic Server
CVE-2026-9190HTTP request smuggling in Progress MarkLogic ServerProgress Software Corporation MarkLogic Server
CVE-2026-8801File Extension Restriction Bypass in MOVEit TransferProgress MOVEit Transfer
CVE-2026-8800Cross-Org External Token Metadata accessible to AuditUser roleProgress MOVEit Transfer
CVE-2026-8709Privilege escalation in Progress MarkLogic Server REST document patch operationProgress Software Corporation MarkLogic Server
CVE-2026-8668Hardcoded credentials in embedded contentProgress Chef Chef360
CVE-2026-8651IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit TransferProgress MOVEit Transfer
CVE-2026-8650Authenticated Path Traversal allows MOVEit admins to view arbitrary system filesProgress MOVEit Transfer
CVE-2026-8649Institution scope bypass vulnerability in custom reportsProgress MOVEit Transfer
CVE-2026-8488Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationProgress Software MOVEit Automation
CVE-2026-8487Incorrect default permissions vulnerability in Progress Software MOVEit AutomationProgress Software MOVEit Automation
CVE-2026-8486Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit AutomationProgress Software MOVEit Automation
CVE-2026-8485Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit AutomationProgress Software MOVEit Automation
CVE-2026-8100no title heldProgress Chef Chef360
CVE-2026-8079Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress FlowmonProgress Software Flowmon
CVE-2026-80462Privilege Escalation in Progress Chef AutomateProgress Software Chef Automate
CVE-2026-8037OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale…Progress Software MOVEit WAF
CVE-2026-7557SAML authentication bypass in Progress MarkLogic ServerProgress Software Corporation MarkLogic Server
CVE-2026-7329Privilege escalation in Progress MarkLogic Server REST query interfacesProgress Software Corporation MarkLogic Server
CVE-2026-7327Privilege escalation in Progress MarkLogic Server REST API document processingProgress Software Corporation MarkLogic Server
CVE-2026-7326Cross-site request forgery in Progress MarkLogic Server Admin UIProgress Software Corporation MarkLogic Server
CVE-2026-7313CWE‑522: Insufficiently Protected Credentials in web services in Progress SitefinityProgress Software Sitefinity
CVE-2026-7312CWE‑522: Insufficiently Protected Credentials in web services in Progress SitefinityProgress Software Sitefinity
CVE-2026-7201CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress SitefinityProgress Software Sitefinity
CVE-2026-7198CWE-284: Improper Access Control in web services in Progress SitefinityProgress Software Sitefinity
CVE-2026-7195CWE-20: Improper Input Validation in web services in Progress SitefinityProgress Software Sitefinity
CVE-2026-65941WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal…Progress Software Corporation WhatsUp Gold
CVE-2026-65940WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary…Progress Software Corporation WhatsUp Gold
CVE-2026-65939WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.Progress Software Corporation WhatsUp Gold
CVE-2026-65938WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.Progress Software Corporation WhatsUp Gold
CVE-2026-65937WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web…Progress Software Corporation WhatsUp Gold
CVE-2026-6023Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-6022Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-59690Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing…Progress Software Multi Tenant
CVE-2026-59689Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization…Progress Software MOVEit WAF
CVE-2026-59688Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via…Progress Software MOVEit WAF
CVE-2026-59687Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via…Progress Software MOVEit WAF
CVE-2026-59686Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via…Progress Software MOVEit WAF
CVE-2026-5174Improper Access Control Vulnerability in Progress MOVEit AutomationProgress Software MOVEit Automation
CVE-2026-4670Improper Authentication vulnerability in Progress MOVEit AutomationProgress Software MOVEit Automation
CVE-2026-4048OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale…Progress Software MOVEit WAF
CVE-2026-3692Unintended command execution during report generation in Progress FlowmonProgress Software Flowmon
CVE-2026-3519OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale…Progress Software MOVEit WAF
CVE-2026-3518OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale…Progress Software MOVEit WAF
CVE-2026-3517OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale…Progress Software MOVEit WAF
CVE-2026-2878Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-2737Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web applicationProgress Software Flowmon
CVE-2026-2701RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)Progress ShareFile Storage Zones Controller
CVE-2026-2699EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)Progress ShareFile Storage Zones Controller
CVE-2026-25373WordPress Vayvo - Media Streaming & Membership WordPress Theme theme < 6.8 - Reflected Cross Site Scripting (XSS)…ProgressionStudios Vayvo
CVE-2026-2514Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon ADS web applicationProgress Software Flowmon ADS
CVE-2026-2513Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon ADS web…Progress Software Flowmon ADS
CVE-2026-19219DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-18672RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-16139Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote…Progress ShareFile Storage Zones Controller
CVE-2026-16138Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO serviceProgress ShareFile Storage Zones Controller
CVE-2026-16137Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones…Progress ShareFile Storage Zones Controller
CVE-2026-15968Stored XSS vulnerability in MOVEit TransferProgress MOVEit Transfer
CVE-2026-15967MOVEit Transfer refresh-token processing does not enforce updated account restrictionsProgress MOVEit Transfer
CVE-2026-15966Improper CORS handling in MOVEit TransferProgress MOVEit Transfer
CVE-2026-15724Path traversal in Progress ShareFile Storage Zones Controller (SZC)Progress ShareFile Storage Zones Controller
CVE-2026-14932Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChartProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-14865XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13192RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13190PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13189SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13188DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13187DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13186AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13185PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13184RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13183RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13182RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-13181RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2026-11903Stored XSS in MOVEit Transfer Ad Hoc moduleProgress MOVEit Transfer
CVE-2026-10699Memory leak in SFTP service can result in a denial of service in MOVEit TransferProgress MOVEit Transfer
CVE-2026-10698Table scope bypass vulnerability in custom reportsProgress MOVEit Transfer
CVE-2026-10697MFA Bypass in MOVEit TransferProgress MOVEit Transfer
CVE-2025-8868Chef Automate compliance service SQL Injection VulnerabilityProgress Software Chef Automate
CVE-2025-8095Recoverable obfuscation using the OECH1 prefix encoding in OpenEdgeProgress Software Corporation OpenEdge
CVE-2025-7389Unauthorized Arbitrary File Read via RMI in AdminServer InterfaceProgress Software Corporation OpenEdge
CVE-2025-7388Authenticated Command Injection via configuration parameter manipulation in exposed RMI interfaceProgress Software Corporation OpenEdge
CVE-2025-6725Cross-Site Scripting (XSS) in PdfViewerProgress Software Telerik UI for Blazor
CVE-2025-6724Chef Automate SQL Injection VulnerabilityProgress Software Chef Automate
CVE-2025-6723Untrusted user data can lead to privilege escalationProgress Software Chef Inspec
CVE-2025-6505no title heldProgress Software Hybrid Data Pipeline
CVE-2025-6504Possibilities of IP Spoofing via X-Forwarded-For (XFF) HeaderProgress Software Hybrid Data Pipeline
CVE-2025-48082WordPress Progress Planner plugin <= 1.8.0 - Privilege Escalation vulnerabilityProgress Planner
CVE-2025-3600Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAXProgress Software Telerik UI for ASP.NET AJAX
CVE-2025-2572WhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2025-2324A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folderProgress MOVEit Transfer
CVE-2025-1968no title heldProgress Software Corporation Sitefinity
CVE-2025-1758no title heldProgress LoadMaster
CVE-2025-13774SQL injection leading to privilege escalation in Progress Flowmon ADSProgress Software Flowmon ADS
CVE-2025-13447OS Command Injection Remote Code Execution Vulnerability in Progress LoadMasterProgress Software LoadMaster
CVE-2025-13444OS Command Injection Remote Code Execution Vulnerability in Progress LoadMasterProgress Software Multi Tenant LoadMaster
CVE-2025-13147External Service Interaction (DNS)Progress MOVEit Transfer
CVE-2025-11906Privilege escalation via writable configuration files in Progress FlowmonProgress Software Flowmon
CVE-2025-11235MOVEit Transfer REST API does not require current password in order to initiate the password change processProgress MOVEit Transfer
CVE-2025-10932AS2 module allows uncontrolled file uploadsProgress MOVEit Transfer
CVE-2025-10703no title heldProgress DataDirect OpenAccess JDBC Driver
CVE-2025-10702no title heldProgress DataDirect OpenAccess JDBC Driver
CVE-2025-10240Possibility of unintended actions when a user clicks a malicious link in the Progress Flowmon web applicationProgress Software Flowmon
CVE-2025-10239Unintended command execution via troubleshooting scripts in Progress FlowmonProgress Software Flowmon
CVE-2025-0556Telerik Report Server Clear Text Transmission of Agent CommandsProgress Software Telerik Report Server
CVE-2025-0332Progress UI for WinForms decompression path traversal vulnerabilityProgress Software Progress® Telerik® UI for WinForms
CVE-2024-9999Multi-Factor Authentication Bypass in Progress WS_FTP ServerProgress Software Corporation WS_FTP Server
CVE-2024-9825The Chef Habitat builder is impacted by Indirect Object reference(IDOR) by deletion of personal access tokenProgress Software Corporation Chef Habitat Builder
CVE-2024-8785WhatsUp Gold Registry Overwrite Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-8755Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Progress LoadMaster
CVE-2024-8316Progress UI for WPF format provider unsafe deserialization vulnerabilityProgress Software Telerik UI for WPF
CVE-2024-8049Telerik Document Processing Improper Handling of Memory ResourcesProgress Software Telerik Document Processing Libraries
CVE-2024-8048Telerik Reporting Insecure Expression EvaluationProgress Software Telerik Reporting
CVE-2024-8015Telerik Report Server Insecure Type ResolutionProgress Software Telerik Reporting
CVE-2024-8014Telerik Reporting EntityDataSource Insecure Type ResolutionProgress Software Telerik Reporting
CVE-2024-7840Improper neutralization special element in hyperlinksProgress Software Telerik Reporting
CVE-2024-7763WhatsUp Gold getReport Missing Authentication Authentication Bypass VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-7745Multi-Factor Authentication Bypass in Progress WS_FTP ServerProgress Software Corporation WS_FTP Server
CVE-2024-7744Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP ServerProgress Software Corporation WS_FTP Server
CVE-2024-7679Improper neutralization special element in hyperlinksProgress Software Telerik UI for WinForms
CVE-2024-7654Unauthenticated Content Injection in OpenEdge Management web interface via ActiveMQ discovery serviceProgress OpenEdge
CVE-2024-7591Improper Input Validation vulnerability in Progress LoadMaster allows OS Command InjectionProgress LoadMaster
CVE-2024-7576Progress UI for WPF format provider unsafe deserialization vulnerabilityProgress Software Telerik UI for WPF
CVE-2024-7575Improper neutralization special element in hyperlinksProgress Software Telerik UI for WPF
CVE-2024-7346Client connections using default TLS certificates from OpenEdge may bypass TLS host name validationProgress OpenEdge
CVE-2024-7345Direct local client connections to MS Agents can bypass authenticationProgress OpenEdge
CVE-2024-7295Hard-coded credentials used for temporary and cache data encryptionProgress Software Corporation Telerik Report Server
CVE-2024-7294Uncontrolled resource consumption of anonymous endpointsProgress Software Corporation Telerik Report Server
CVE-2024-7293Password policy for new users is not strong enoughProgress Software Corporation Telerik Report Server
CVE-2024-7292Account Controller allows high count of login attemptsProgress Software Corporation Telerik Report Server
CVE-2024-6672WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-6671WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-6670WhatsUp Gold HasErrors SQL Injection Authentication Bypass VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-6658Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.Progress LoadMaster
CVE-2024-6576MOVEit Transfer Privilege Escalation VulnerabilityProgress MOVEit Transfer
CVE-2024-6327Progress Telerik Report Server DeserializationProgress Software Corporation Telerik Report Server
CVE-2024-6097Absolute Path Traversal VulnerabilityProgress Software Corporation Progress® Telerik® Reporting
CVE-2024-6096Unsafe Deserialization VulnerabilityProgress Software Corporation Telerik Reporting
CVE-2024-5806MOVEit Transfer Authentication Bypass VulnerabilityProgress MOVEit Transfer
CVE-2024-5805MOVEit Gateway Authentication Bypass VulnerabilityProgress MOVEit Gateway
CVE-2024-56135Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Progress LoadMaster
CVE-2024-56134Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Progress LoadMaster
CVE-2024-56133Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Progress LoadMaster
CVE-2024-56132Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Progress LoadMaster
CVE-2024-56131Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.Progress LoadMaster
CVE-2024-5019WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5018WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5017WhatsUp Gold AppProfileImport path traversal vulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5016WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5015WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5014WhatsUp Gold GetASPReport Server-Side Request Forgery Information DisclosureProgress Software Corporation WhatsUp Gold
CVE-2024-5013WhatsUp Gold InstallController Denial-of-Service VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5012WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5011WhatsUp Gold TestController Chart denial of service vulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5010WhatsUp Gold TestController multiple information disclosure vulnerabilitiesProgress Software Corporation WhatsUp Gold
CVE-2024-5009WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-5008WhatsUp Gold APM Unrestricted File Upload Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-4885WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-4884WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-4883WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-4882URL Redirection to Arbitrary Site Exists in SitefinityProgress Software Corporation Sitefinity
CVE-2024-4837Trust Boundary Violation VulnerabilityProgress Software Telerik Report Server
CVE-2024-46909WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-46908WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-46907WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-46906WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-46905WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation VulnerabilityProgress Software Corporation WhatsUp Gold
CVE-2024-4563The Progress MOVEit Automation Configuration Export Function Uses a Cryptographic Method with Insufficient Bit LengthProgress Software Corporation MOVEit Automation
CVE-2024-4562WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via HttpMonitorSettingsProgress Software Corporation WhatsUp Gold
CVE-2024-4561WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via FaviconControllerProgress Software Corporation WhatsUp Gold
CVE-2024-4358Registration Authentication Bypass VulnerabilityProgress Software Corporation Telerik Report Server
CVE-2024-4357XML External Entity Processing Information DisclosureProgress Software Telerik Report Server
CVE-2024-4202Progress Telerik Reporting Local Instantiation VulnerabilityProgress Software Corporation Telerik Reporting
CVE-2024-4200Progress Telerik Reporting Local Deserialization VulnerabilityProgress Software Corporation Telerik Reporting
CVE-2024-3892Local code execution vulnerability in Telerik UI for WinFormsProgress Software Corporation Telerik UI for WinForms
CVE-2024-37422WordPress Progress Planner plugin <= 0.9.2 - Cross Site Scripting (XSS) vulnerabilityProgress Planner
CVE-2024-37411WordPress Progress Planner plugin <= 0.9.1 - Broken Access Control vulnerabilityProgress Planner
CVE-2024-3544LoadMaster Hardcoded SSH KeyProgress Software Corporation LoadMaster
CVE-2024-3543LoadMaster Reversible Password Encryption AlgorithmProgress Software Corporation LoadMaster
CVE-2024-2449LoadMaster Cross-Site Request Forgery (CSRF)Progress Software LoadMaster
CVE-2024-2448LoadMaster Command Injection VulnerabilityProgress Software LoadMaster
CVE-2024-2389Flowmon Unauthenticated Command Injection VulnerabilityProgress Software Flowmon
CVE-2024-2291MOVEit Transfer Logging Bypass VulnerabilityProgress Software MOVEit Transfer
CVE-2024-1856Progress Telerik Reporting Remote Deserialization VulnerabilityProgress Software Corporation Telerik Reporting
CVE-2024-1801Progress Telerik Reporting Local Deserialization VulnerabilityProgress Software Corporation Telerik Reporting
CVE-2024-1800Progress Telerik Report Server DeserializationProgress Software Corporation Telerik Report Server
CVE-2024-1636Potential Cross-Site Scripting (XSS) in the page editing areaProgress Software Corporation Sitefinity
CVE-2024-1632Incorrect access control in the Sitefinity backendProgress Software Corporation Sitefinity
CVE-2024-1474WS_FTP Server Reflected Cross-Site Scripting in Administrative InterfaceProgress Software Coproration WS_FTP Server
CVE-2024-1403Authentication Bypass in OpenEdge Authentication Gateway and AdminServerProgress OpenEdge
CVE-2024-12629Prototype Pollution in Progress® Telerik® KendoReactProgress Software Telerik KendoReact
CVE-2024-12251Improper neutralization special element in hyperlinksProgress Software Telerik UI for WinUI
CVE-2024-1212LoadMaster Pre-Authenticated OS Command InjectionProgress Software LoadMaster
CVE-2024-12108WhatsUp Gold - Public API signing key rotation issueProgress Software Corporation WhatsUp Gold
CVE-2024-12106WhatsUp Gold - LDAP configuration interface leading to allowing attacker to configure LDAP settings without…Progress Software Corporation WhatsUp Gold
CVE-2024-12105WhatsUp Gold - SnmpExtendedActiveMonitor path traversalProgress Software Corporation WhatsUp Gold

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.