VYPR

Vendor CVEs

Progress (organisation)

All CVEs

323 total · sorted by risk
  • CVE-2026-10697HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

  • CVE-2026-8801LowJul 8, 2026
    risk 0.00cvss 3.5epss 0.00

    Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

  • CVE-2026-8800LowJul 8, 2026
    risk 0.00cvss 2.7epss 0.00

    Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

  • CVE-2026-8651LowJul 8, 2026
    risk 0.00cvss 3.7epss 0.00

    Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

  • CVE-2026-8650MedJul 8, 2026
    risk 0.00cvss 4.5epss 0.00

    Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

  • CVE-2026-8649MedJul 8, 2026
    risk 0.00cvss 6.4epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

  • CVE-2026-11903HigJul 8, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8.

  • CVE-2026-10699HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.

  • CVE-2026-10698HigJul 8, 2026
    risk 0.00cvss 7.2epss 0.01

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1.

  • CVE-2026-9272HigJul 2, 2026
    risk 0.00cvss 8.1epss 0.00

    In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to…

  • CVE-2026-8079HigJul 2, 2026
    risk 0.00cvss 7.3epss 0.00

    In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading…

  • CVE-2014-2217Dec 25, 2014
    risk 0.00cvss epss 0.04

    Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata…

  • CVE-2007-3491Jun 29, 2007
    risk 0.00cvss epss 0.03

    Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.

  • CVE-2007-2602May 11, 2007
    risk 0.00cvss epss 0.03

    Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary code via a long MIB filename argument. NOTE: If there is not a common scenario under which MIBEXTRA.EXE is called with…

  • CVE-2007-2354Apr 30, 2007
    risk 0.00cvss epss 0.02

    Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", which reveals the operating system and product information.

  • CVE-2007-2266Apr 25, 2007
    risk 0.00cvss epss 0.02

    Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file…

  • CVE-2004-1885Dec 31, 2004
    risk 0.00cvss epss 0.04

    Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.

  • CVE-2004-0799Oct 20, 2004
    risk 0.00cvss epss 0.06

    The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".

  • CVE-2004-1884Mar 23, 2004
    risk 0.00cvss epss 0.06

    Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.

  • CVE-2003-0485Aug 7, 2003
    risk 0.00cvss epss 0.01

    Buffer overflow in Progress 4GL Compiler 9.1D06 and earlier allows attackers to execute arbitrary code via source code containing a long, invalid data type.

  • CVE-2001-1129Nov 2, 2001
    risk 0.00cvss epss 0.00

    Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6) _progres, (7) _proutil, (8) _rfutil and (9) prolib in Progress database 9.1C allows a local user to execute arbitrary code via format string specifiers in the file used by…

  • CVE-2001-1128Oct 8, 2001
    risk 0.00cvss epss 0.01

    Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment variables.

  • CVE-2000-0127Feb 3, 2000
    risk 0.00cvss epss 0.04

    The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsisa.dll.

Page 7 of 7