VYPR

Vendor CVEs

Progress (organisation)

All CVEs

323 total · sorted by risk
  • CVE-2024-10013HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-8048HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

  • CVE-2024-7840HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.01

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

  • CVE-2024-0833HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to…

  • CVE-2024-0832HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the…

  • CVE-2024-0219HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to…

  • CVE-2022-29849HigMay 2, 2022
    risk 0.51cvss 7.8epss 0.00

    In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the affected system.

  • CVE-2019-12097HigJun 3, 2019
    risk 0.51cvss 7.8epss 0.01

    Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privilege escalation by replacing the original EnableLoopback.exe.

  • CVE-2026-5174HigApr 30, 2026
    risk 0.50cvss 7.7epss 0.03

    Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0.

  • CVE-2025-3600HigMay 14, 2025
    risk 0.50cvss 7.5epss 0.20

    In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.

  • CVE-2025-1968HigApr 9, 2025
    risk 0.50cvss 7.7epss 0.00

    Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from…

  • CVE-2024-11625HigJan 7, 2025
    risk 0.50cvss 7.7epss 0.00

    Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

  • CVE-2024-4202HigMay 15, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.

  • CVE-2024-4200HigMay 15, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

  • CVE-2024-2449HigMar 22, 2024
    risk 0.50cvss 7.5epss 0.13

    A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site. In such a…

  • CVE-2024-1801HigMar 20, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

  • CVE-2026-7326HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can…

  • CVE-2026-13189HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.

  • CVE-2026-13184HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload…

  • CVE-2026-13183HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

  • CVE-2026-13182HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

  • CVE-2026-6022HigApr 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk…

  • CVE-2024-7294HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.

  • CVE-2024-7293HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.

  • CVE-2024-7292HigOct 9, 2024
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.

  • CVE-2024-5016HigJun 25, 2024
    risk 0.49cvss 7.2epss 0.22

    In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM.  The vulnerability exists in the main message processing routines NmDistributed.DistributedServic…

  • CVE-2024-5013HigJun 25, 2024
    risk 0.49cvss 7.5epss 0.01

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step, which renders the application non-accessible.

  • CVE-2024-3544HigMay 2, 2024
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the machines in the HA or Cluster group. This vulnerability has been closed by enhancing LoadMaster partner communications to require…

  • CVE-2024-1474HigFeb 21, 2024
    risk 0.49cvss 7.5epss 0.00

    In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.

  • CVE-2023-40052HigJan 18, 2024
    risk 0.49cvss 7.5epss 0.01

    This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 .  An attacker who can produce a malformed web request may cause the crash of a PASOE agent potentially…

  • CVE-2023-6595HigDec 14, 2023
    risk 0.49cvss 7.5epss 0.01

    In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate ancillary credential information stored within WhatsUp Gold.

  • CVE-2023-6367HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Roles.   If a WhatsUp Gold user interacts with the crafted payload, the…

  • CVE-2023-6366HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within Alert Center.   If a WhatsUp Gold user interacts with the crafted…

  • CVE-2023-6365HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attacker to craft a XSS payload and store that value within a device group.   If a WhatsUp Gold user interacts with the crafted…

  • CVE-2023-6364HigDec 14, 2023
    risk 0.49cvss 7.6epss 0.01

    In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.  It is possible for an attacker to craft a XSS payload and store that value within a dashboard component.   If a WhatsUp Gold user interacts with the…

  • CVE-2023-26101HigApr 21, 2023
    risk 0.49cvss 7.5epss 0.01

    In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vulnerability to retrieve files on the Flowmon appliance's local filesystem.

  • CVE-2019-12145HigJun 11, 2019
    risk 0.49cvss 7.5epss 0.05

    A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string using special patterns via the SCP protocol to disclose path names on the host operating system.

  • CVE-2018-17055HigSep 28, 2018
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.

  • CVE-2017-1000026HigJul 17, 2017
    risk 0.49cvss 7.5epss 0.02

    Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries

  • CVE-2024-6576HigJul 29, 2024
    risk 0.48cvss 7.3epss 0.01

    Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.

  • CVE-2025-10239HigOct 9, 2025
    risk 0.47cvss 7.2epss 0.00

    In Flowmon versions prior to 12.5.5, a vulnerability has been identified that allows a user with administrator privileges and access to the management interface to execute additional unintended commands within scripts intended for troubleshooting purposes.

  • CVE-2024-7346HigSep 3, 2024
    risk 0.47cvss 7.2epss 0.00

    Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection.  This has been corrected so that default certificates are no longer capable of overriding host name…

  • CVE-2024-3892HigMay 15, 2024
    risk 0.47cvss 7.2epss 0.00

    A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.

  • CVE-2023-6218HigNov 29, 2023
    risk 0.47cvss 7.2epss 0.01

    In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associated with group administrators has been identified.  It is possible for a group administrator to elevate a group members…

  • CVE-2023-40043HigSep 20, 2023
    risk 0.47cvss 7.2epss 0.01

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vulnerability has been identified in the MOVEit Transfer web interface that could allow a MOVEit system administrator account to…

  • CVE-2023-24029HigFeb 3, 2023
    risk 0.47cvss 7.2epss 0.01

    In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to insufficient authorization controls applied on user modification workflows.

  • CVE-2024-11629HigFeb 12, 2025
    risk 0.46cvss 7.1epss 0.00

    In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.

  • CVE-2024-12105MedDec 31, 2024
    risk 0.46cvss 6.5epss 0.42

    In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.

  • CVE-2024-7295HigNov 13, 2024
    risk 0.46cvss 7.1epss 0.00

    In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.

  • CVE-2024-5015HigJun 25, 2024
    risk 0.46cvss 7.1epss 0.01

    In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges…

Page 4 of 7