VYPR

Vendor CVEs

Progress (organisation)

All CVEs

323 total · sorted by risk
  • CVE-2024-5014HigJun 25, 2024
    risk 0.46cvss 7.1epss 0.00

    In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form.

  • CVE-2024-0396HigJan 17, 2024
    risk 0.46cvss 7.1epss 0.01

    In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can manipulate a parameter in an HTTPS transaction. The modified transaction…

  • CVE-2023-6217HigNov 29, 2023
    risk 0.46cvss 7.1epss 0.01

    In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS) vulnerability has been identified when MOVEit Gateway is used in conjunction with MOVEit Transfer.  An attacker could craft…

  • CVE-2022-29848MedMay 11, 2022
    risk 0.46cvss 6.5epss 0.04

    In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive operating-system attributes from a host that is accessible by the WhatsUp Gold system.

  • CVE-2022-29845MedMay 11, 2022
    risk 0.46cvss 6.5epss 0.04

    In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read the contents of a local file.

  • CVE-2015-6005MedDec 27, 2015
    risk 0.45cvss 6.9epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap message, (3) the View Names field, (4) the Group Names field, (5) the Flow Monitor…

  • CVE-2026-65940MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

  • CVE-2026-65939MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.

  • CVE-2025-11906MedOct 30, 2025
    risk 0.44cvss 6.7epss 0.00

    A vulnerability exists in Progress Flowmon versions prior 12.5.6 where certain system configuration files have incorrect file permissions, allowing a user with access to the default flowmon system user account used for SSH access to potentially escalate privileges to root during…

  • CVE-2024-11627MedJan 7, 2025
    risk 0.44cvss 6.8epss 0.00

    : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.

  • CVE-2023-40048MedSep 27, 2023
    risk 0.44cvss 6.8epss 0.00

    In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST transaction corresponding to a WS_FTP Server administrative function.

  • CVE-2021-41318MedSep 28, 2021
    risk 0.43cvss 6.1epss 0.06

    In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • CVE-2026-14932MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.

  • CVE-2026-13192MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and…

  • CVE-2026-8487MedMay 20, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

  • CVE-2024-8049MedNov 13, 2024
    risk 0.42cvss 6.5epss 0.00

    In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.

  • CVE-2024-9999MedNov 12, 2024
    risk 0.42cvss 6.5epss 0.00

    In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

  • CVE-2024-7745MedAug 28, 2024
    risk 0.42cvss 6.5epss 0.00

    In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

  • CVE-2024-7744MedAug 28, 2024
    risk 0.42cvss 6.5epss 0.01

    In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.   An authenticated…

  • CVE-2024-5017MedJun 25, 2024
    risk 0.42cvss 6.5epss 0.02

    In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure.

  • CVE-2024-4357MedMay 15, 2024
    risk 0.42cvss 6.5epss 0.01

    An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.

  • CVE-2024-3543MedMay 2, 2024
    risk 0.42cvss 6.4epss 0.00

    Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attacker, stolen credentials can be used for arbitrary actions to corrupt the system.

  • CVE-2022-27665MedApr 3, 2023
    risk 0.42cvss 6.1epss 0.33

    Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory…

  • CVE-2019-7215MedJun 6, 2019
    risk 0.42cvss 6.5epss 0.01

    Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account…

  • CVE-2015-6004MedDec 27, 2015
    risk 0.42cvss 6.5epss 0.02

    Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.

  • CVE-2026-2737MedApr 2, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.

  • CVE-2024-4563MedMay 22, 2024
    risk 0.40cvss 6.1epss 0.00

    The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.

  • CVE-2023-42656MedSep 20, 2023
    risk 0.40cvss 6.1epss 0.00

    In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-site scripting (XSS) vulnerability has been identified in MOVEit Transfer's web interface.  An attacker could craft a malicious…

  • CVE-2023-35759MedJun 23, 2023
    risk 0.40cvss 6.1epss 0.02

    In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

  • CVE-2023-26100MedApr 21, 2023
    risk 0.40cvss 6.1epss 0.00

    In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could leverage a reflected XSS vulnerability to execute arbitrary code within the context of a Flowmon user's web browser.

  • CVE-2022-36967MedAug 2, 2022
    risk 0.40cvss 6.1epss 0.01

    In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would…

  • CVE-2020-12677MedMay 14, 2020
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, which could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS. This affects 2018 - 2018.0…

  • CVE-2017-18639MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : List Title, /Content/Documents/LibraryDocuments/incident-request-attachments Parameter : Document Title,…

  • CVE-2018-17054MedOct 3, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17053.

  • CVE-2018-17053MedOct 3, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054.

  • CVE-2018-17056MedSep 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2018-14037MedSep 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the…

  • CVE-2017-18178MedFeb 12, 2018
    risk 0.40cvss 6.1epss 0.02

    Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.

  • CVE-2017-9140MedMay 22, 2017
    risk 0.40cvss 6.1epss 0.10

    Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to…

  • CVE-2026-13188MedJul 22, 2026
    risk 0.38cvss 5.9epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.

  • CVE-2026-8485MedMay 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7.

  • CVE-2025-2324MedMar 19, 2025
    risk 0.38cvss 5.9epss 0.00

    Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12, from 2024.0.0 before 2024.0.8, from 2024.1.0 before…

  • CVE-2023-27636MedJun 16, 2024
    risk 0.38cvss 5.4epss 0.01

    Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

  • CVE-2023-6368MedDec 14, 2023
    risk 0.38cvss 5.9epss 0.01

    In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthenticated attacker to enumerate information related to a registered device being monitored by WhatsUp Gold.

  • CVE-2023-34363MedJun 9, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption…

  • CVE-2022-29846MedMay 11, 2022
    risk 0.38cvss 5.3epss 0.05

    In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obtain the WhatsUp Gold installation serial number.

  • CVE-2025-2572MedApr 14, 2025
    risk 0.36cvss 5.6epss 0.00

    In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup.

  • CVE-2023-28864MedJul 17, 2023
    risk 0.36cvss 5.5epss 0.00

    Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are…

  • CVE-2024-5019MedJun 25, 2024
    risk 0.35cvss 5.3epss 0.01

    In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

  • CVE-2024-5018MedJun 25, 2024
    risk 0.35cvss 5.3epss 0.01

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory .

Page 5 of 7