VYPR

Vendor CVEs

Progress (organisation)

All CVEs

323 total · sorted by risk
  • CVE-2018-5777CriJan 24, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP server that could allow attackers to execute arbitrary commands on the TFTP server via unspecified vectors.

  • CVE-2017-15883CriJan 8, 2018
    risk 0.64cvss 9.8epss 0.02

    Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.

  • CVE-2015-9245CriOct 31, 2017
    risk 0.64cvss 9.8epss 0.02

    Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.

  • CVE-2024-12108CriDec 31, 2024
    risk 0.63cvss 9.6epss 0.07

    In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

  • CVE-2024-12106CriDec 31, 2024
    risk 0.62cvss 9.4epss 0.10

    In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

  • CVE-2022-42711CriOct 12, 2022
    risk 0.62cvss 9.6epss 0.01

    In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • CVE-2014-5287HigJan 8, 2020
    risk 0.61cvss 8.8epss 0.08

    A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

  • CVE-2024-46906HigDec 2, 2024
    risk 0.60cvss 8.8epss 0.41

    In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

  • CVE-2024-5805CriJun 25, 2024
    risk 0.60cvss 9.1epss 0.08

    Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.

  • CVE-2023-35036CriJun 12, 2023
    risk 0.60cvss 9.1epss 0.13

    In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…

  • CVE-2026-9190CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs…

  • CVE-2026-7557CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This…

  • CVE-2025-8095CriApr 14, 2026
    risk 0.59cvss epss 0.00

    The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications.  OECH1 encodings should be considered exploitable and immediately replaced…

  • CVE-2024-8015CriOct 9, 2024
    risk 0.59cvss 9.1epss 0.01

    In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.

  • CVE-2024-5008HigJun 25, 2024
    risk 0.59cvss 8.8epss 0.17

    In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

  • CVE-2024-2448HigMar 22, 2024
    risk 0.59cvss 8.4epss 0.55

    An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

  • CVE-2023-40051CriJan 18, 2024
    risk 0.59cvss 9.1epss 0.01

    This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory…

  • CVE-2023-42659CriNov 7, 2023
    risk 0.59cvss 9.1epss 0.01

    In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has the ability to craft an API call which allows them to upload a file to a specified location on the underlying operating system…

  • CVE-2023-36932HigJul 5, 2023
    risk 0.59cvss 8.1epss 0.81

    In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), multiple SQL injection vulnerabilities have been identified in the MOVEit Transfer web application that could allow an…

  • CVE-2020-8612CriFeb 14, 2020
    risk 0.59cvss 9.0epss 0.02

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

  • CVE-2019-12146CriJun 11, 2019
    risk 0.59cvss 9.1epss 0.04

    A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their…

  • CVE-2026-65941HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • CVE-2026-7313HigJun 2, 2026
    risk 0.57cvss 8.7epss 0.00

    CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active…

  • CVE-2026-7201HigJun 2, 2026
    risk 0.57cvss 8.8epss 0.00

    CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading…

  • CVE-2026-7195HigJun 2, 2026
    risk 0.57cvss 8.8epss 0.00

    CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote…

  • CVE-2026-3692HigApr 2, 2026
    risk 0.57cvss 8.8epss 0.00

    In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.

  • CVE-2025-13447HigJan 13, 2026
    risk 0.57cvss 8.4epss 0.27

    OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

  • CVE-2025-13444HigJan 13, 2026
    risk 0.57cvss 8.4epss 0.27

    OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

  • CVE-2025-13774HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.

  • CVE-2025-48082HigOct 22, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in Progress Planner Progress Planner progress-planner allows Privilege Escalation.This issue affects Progress Planner: from n/a through <= 1.8.0.

  • CVE-2025-10240HigOct 9, 2025
    risk 0.57cvss 8.8epss 0.00

    A vulnerability exists in the Progress Flowmon web application prior to version 12.5.5, whereby a user who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated session.

  • CVE-2025-0556HigFeb 12, 2025
    risk 0.57cvss 8.8epss 0.00

    In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be…

  • CVE-2024-46908HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.02

    In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

  • CVE-2024-46907HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.02

    In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

  • CVE-2024-46905HigDec 2, 2024
    risk 0.57cvss 8.8epss 0.02

    In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.

  • CVE-2024-8014HigOct 9, 2024
    risk 0.57cvss 8.8epss 0.01

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.

  • CVE-2024-6672HigAug 29, 2024
    risk 0.57cvss 8.8epss 0.01

    In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.

  • CVE-2024-6096HigJul 24, 2024
    risk 0.57cvss 8.8epss 0.01

    In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

  • CVE-2024-1632HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

  • CVE-2023-42658HigOct 31, 2023
    risk 0.57cvss 8.8epss 0.00

    Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

  • CVE-2023-42660HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer machine interface that could allow an authenticated attacker to gain…

  • CVE-2023-34203HigJun 23, 2023
    risk 0.57cvss 8.8epss 0.01

    In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x…

  • CVE-2021-37614HigAug 5, 2021
    risk 0.57cvss 8.8epss 0.01

    In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authenticated remote attacker to gain access to the database. Depending on the database engine being used (MySQL, Microsoft SQL Server,…

  • CVE-2021-33894HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (12.0.5), 2020.1.x before 2020.1.4 (12.1.4), and 2021.x before 2021.0.1 (13.0.1), a SQL injection vulnerability exists in…

  • CVE-2021-31827HigMay 18, 2021
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL,…

  • CVE-2020-8611HigFeb 14, 2020
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending…

  • CVE-2017-18179HigFeb 12, 2018
    risk 0.57cvss 8.8epss 0.03

    Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termination. Also, it is transmitted as a GET parameter. This is fixed in 10.1.

  • CVE-2016-1000000HigOct 6, 2016
    risk 0.57cvss 8.8epss 0.01

    Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection

  • CVE-2026-8100HigJun 18, 2026
    risk 0.56cvss epss 0.01

    Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated…

  • CVE-2026-3518HigApr 20, 2026
    risk 0.56cvss 8.4epss 0.20

    OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command

Page 2 of 7