Skip to content
Noroxi

Progress records

301 published records for vendor progress.

All records

301 records
  • In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    progress · moveit cloudJun 2, 2023

  • WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    progress · whatsup goldJun 25, 2024

  • LoadMaster Pre-Authenticated OS Command Injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 95%

    progress · loadmasterFeb 21, 2024

  • WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    progress · whatsup goldAug 29, 2024

  • WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 91%

    progress · ws ftp serverSep 27, 2023

  • Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke

    CriticalCVSS 9.8KEVWeaponizedEPSS 78%

    progress · telerik ui for asp.net ajaxAug 23, 2017

  • OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

    CriticalCVSS 9.8KEVWeaponizedEPSS 77%

    progress · connection manager for objectscaleJun 4, 2026

  • Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te

    CriticalCVSS 9.8KEVWeaponizedEPSS 75%

    progress · sitefinityJul 3, 2017

  • CVE-2023-35708
    68This week

    In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL

    CriticalCVSS 9.8Proof of conceptEPSS 97%

    progress · moveit transferJun 16, 2023

  • CVE-2024-2389
    67This week

    Flowmon Unauthenticated Command Injection Vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 93%

    progress · flowmonApr 2, 2024

  • CVE-2023-36934
    65This week

    In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023

    CriticalCVSS 9.1Proof of conceptEPSS 95%

    progress · moveit transferJul 5, 2023

  • CVE-2024-5806
    63This week

    MOVEit Transfer Authentication Bypass Vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 81%

    progress · moveit transferJun 25, 2024

  • WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 65%

    progress · whatsup goldJun 25, 2024

  • In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023

    HighCVSS 8.1No exploitEPSS 81%

    progress · moveit transferJul 5, 2023

  • Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary cod

    HighCVSS 7.5Proof of conceptEPSS 85%

    ipswitch · ws ftp serverSep 22, 2003

  • WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 49%

    progress · whatsup goldDec 2, 2024

  • Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long

    MediumCVSS 6.5WeaponizedEPSS 85%

    ipswitch · ws ftp serverSep 18, 2006

  • In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is

    HighCVSS 7.5No exploitEPSS 72%

    progress · moveit transferJul 5, 2023

  • LoadMaster Command Injection Vulnerability

    HighCVSS 8.8No exploitEPSS 55%

    progress · loadmasterMar 22, 2024

  • WhatsUp Gold TestController multiple information disclosure vulnerabilities

    HighCVSS 7.5No exploitEPSS 70%

    progress · whatsup goldJun 25, 2024

  • Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary co

    HighCVSS 7.5WeaponizedEPSS 63%

    progress · whatsup goldOct 20, 2004

  • In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transac

    HighCVSS 7.5WeaponizedEPSS 58%

    progress · whatsup goldMay 11, 2022

  • Progress Telerik Report Server Deserialization

    HighCVSS 8.8WeaponizedEPSS 40%

    progress · telerik report serverMar 20, 2024

  • WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability

    HighCVSS 8.8No exploitEPSS 40%

    progress · whatsup goldDec 2, 2024

  • WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 24%

    progress · whatsup goldJun 25, 2024