progress

244 tracked vulnerabilities.

CVE-2024-7745 MEDIUM
WS_FTP Server <8.8.8 - Privilege Escalation
Aug 28, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-7744 MEDIUM
WS_FTP Server < 8.8.8 - Authenticated Path Traversal via Web Transfer Module
Aug 28, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-6576 HIGH
Progress MOVEit Transfer - Privilege Escalation
Jul 29, 2024
CVSS 7.3
EPSS 0.02
CVE-2024-6327 CRITICAL
Telerik Report Server <2024 Q2 - Code Injection
Jul 24, 2024
CVSS 9.9
EPSS 0.03
CVE-2024-6096 HIGH
Telerik Reporting <18.1.24.709 - Code Injection
Jul 24, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-5019 MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Arbitrary File Read via SessionController.CachedCSS
Jun 25, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-5018 MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Path Traversal via SessionController.LoadNMScript
Jun 25, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-5017 MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Path Traversal via AppProfileImport
Jun 25, 2024
CVSS 6.5
EPSS 0.01
CVE-2024-5016 HIGH
WhatsUp Gold < 23.1.0 - Remote Code Execution via Untrusted Data Deserialization
Jun 25, 2024
CVSS 7.2
EPSS 0.06
CVE-2024-5015 HIGH
WhatsUp Gold < 23.1.3 - Authenticated Server-Side Request Forgery in SessionController
Jun 25, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-5014 HIGH
WhatsUp Gold < 23.1.3 - Authenticated Server-Side Request Forgery via GetASPReport Feature
Jun 25, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-5013 HIGH
WhatsUp Gold < 23.1.3 - Unauthenticated Denial of Service via SetAdminPassword Installation Step
Jun 25, 2024
CVSS 7.5
EPSS 0.01
CVE-2024-5012 HIGH
WhatsUp Gold < 23.1.3 - Unauthenticated Windows Credential Disclosure via WUGDataAccess.Credentials
Jun 25, 2024
CVSS 8.6
EPSS 0.01
CVE-2024-5011 HIGH
WhatsUp Gold < 23.1.3 - Unauthenticated Denial of Service via TestController Chart Request
Jun 25, 2024
CVSS 7.5
EPSS 0.11
CVE-2024-5010 HIGH
WhatsUp Gold < 23.1.3 - Unauthenticated Sensitive Information Exposure via TestController
Jun 25, 2024
CVSS 7.5
EPSS 0.28
CVE-2024-5009 HIGH
WhatsUp Gold < 23.1.3 - Improper Access Control in InstallController.SetAdminPassword
Jun 25, 2024
CVSS 8.4
EPSS 0.36
CVE-2024-5008 HIGH
WhatsUp Gold < 23.1.3 - Authenticated Remote Code Execution via AppProfileImportController
Jun 25, 2024
CVSS 8.8
EPSS 0.32
CVE-2024-4885 CRITICAL KEVNUCLEI
Progress WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via ExportUtilities.Export.GetFileWithoutZip
Jun 25, 2024
CVSS 9.8
EPSS 0.94
CVE-2024-4884 CRITICAL
WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via CommunityController
Jun 25, 2024
CVSS 9.8
EPSS 0.55
CVE-2024-4883 CRITICAL
Progress WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via NmApi.exe
Jun 25, 2024
CVSS 9.8
EPSS 0.92
CVE-2024-5806 CRITICAL
Progress MOVEit SFTP Authentication Bypass for Arbitrary File Read
Jun 25, 2024
CVSS 9.1
EPSS 0.90
CVE-2024-5805 CRITICAL
Progress MOVEit Gateway 2024.0.0.0 - Authentication Bypass in SFTP Modules
Jun 25, 2024
CVSS 9.1
EPSS 0.01
CVE-2024-4563 MEDIUM
Progress MOVEit Automation < 2024.0.0 - Use of a Broken or Risky Cryptographic Algorithm in Configuration Export
May 22, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-4837 MEDIUM
Progress Telerik Report Server < 10.1.24.514 - Sensitive Information Exposure
May 15, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-4357 MEDIUM
Progress Telerik Report Server < 10.1.24.514 - XML External Entity Injection
May 15, 2024
CVSS 6.5
EPSS 0.02