Progress records
301 published records for vendor progress.
Researcher profile
- Entered KEV
- 8 · 2.7%
- Weaponized
- 17 · 5.6%
- Pre-auth RCE
- 37
- With a fix record
- 41.2%
- Median publish → KEV
- 158 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')40
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')27
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')19
- CWE-20 Improper Input Validation13
- CWE-502 Deserialization of Untrusted Data12
- CWE-287 Improper Authentication11
The weakness classes this vendor ships most often: where to look.
CWEAll records
301 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-34362Weaponized | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL progress · moveit cloud · CWE-89 | Critical9.8 | KEV | 99.9% | Jun 2, 2023 |
99Now | CVE-2024-4885Weaponized | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-22 | Critical9.8 | KEV | 99.3% | Jun 25, 2024 |
98Now | CVE-2024-1212Weaponized | LoadMaster Pre-Authenticated OS Command Injectionprogress · loadmaster · CWE-78 | Critical9.8 | KEV | 95.4% | Feb 21, 2024 |
97Now | CVE-2024-6670Weaponized | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-89 | Critical9.8 | KEV | 93.0% | Aug 29, 2024 |
92Now | CVE-2023-40044Weaponized | WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerabilityprogress · ws ftp server · CWE-502 | High8.8 | KEV | 90.6% | Sep 27, 2023 |
92Now | CVE-2017-11357Weaponized | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackeprogress · telerik ui for asp.net ajax · CWE-434 | Critical9.8 | KEV | 77.7% | Aug 23, 2017 |
92Now | CVE-2026-8037Weaponized | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFprogress · connection manager for objectscale · CWE-77 | Critical9.8 | KEV | 77.4% | Jun 4, 2026 |
92Now | CVE-2017-9248Weaponized | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Teprogress · sitefinity · CWE-522 | Critical9.8 | KEV | 75.1% | Jul 3, 2017 |
68This week | CVE-2023-35708Proof of concept | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL progress · moveit transfer · CWE-89 | Critical9.8 | — | 96.7% | Jun 16, 2023 |
67This week | CVE-2024-2389Weaponized | Flowmon Unauthenticated Command Injection Vulnerabilityprogress · flowmon · CWE-78 | Critical9.8 | — | 93.0% | Apr 2, 2024 |
65This week | CVE-2023-36934Proof of concept | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023progress · moveit transfer · CWE-89 | Critical9.1 | — | 95.2% | Jul 5, 2023 |
63This week | CVE-2024-5806Weaponized | MOVEit Transfer Authentication Bypass Vulnerabilityprogress · moveit transfer · CWE-287 | Critical9.8 | — | 81.5% | Jun 25, 2024 |
58Plan | CVE-2024-4883Proof of concept | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-77 | Critical9.8 | — | 64.5% | Jun 25, 2024 |
56Plan | CVE-2023-36932No exploit | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023progress · moveit transfer · CWE-89 | High8.1 | — | 81.1% | Jul 5, 2023 |
55Plan | CVE-2003-0772Proof of concept | Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary codipswitch · ws ftp server | High7.5 | — | 84.9% | Sep 22, 2003 |
54Plan | CVE-2024-46909No exploit | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-16 | Critical9.8 | — | 48.9% | Dec 2, 2024 |
52Plan | CVE-2006-4847Weaponized | Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via longipswitch · ws ftp server | Medium6.5 | — | 85.3% | Sep 18, 2006 |
52Plan | CVE-2023-36933No exploit | In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is progress · moveit transfer · CWE-755 | High7.5 | — | 72.2% | Jul 5, 2023 |
52Plan | CVE-2024-2448No exploit | LoadMaster Command Injection Vulnerabilityprogress · loadmaster · CWE-78 | High8.8 | — | 55.4% | Mar 22, 2024 |
51Plan | CVE-2024-5010No exploit | WhatsUp Gold TestController multiple information disclosure vulnerabilitiesprogress · whatsup gold · CWE-200 | High7.5 | — | 70.0% | Jun 25, 2024 |
49Plan | CVE-2004-0798Weaponized | Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary coprogress · whatsup gold | High7.5 | — | 62.6% | Oct 20, 2004 |
47Plan | CVE-2022-29847Weaponized | In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transacprogress · whatsup gold · CWE-918 | High7.5 | — | 57.6% | May 11, 2022 |
47Plan | CVE-2024-1800Weaponized | Progress Telerik Report Server Deserializationprogress · telerik report server · CWE-502 | High8.8 | — | 40.4% | Mar 20, 2024 |
47Plan | CVE-2024-46906No exploit | WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | High8.8 | — | 40.4% | Dec 2, 2024 |
46Plan | CVE-2024-4884No exploit | WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-77 | Critical9.8 | — | 24.3% | Jun 25, 2024 |
- CVE-2023-3436299Now
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL
CriticalCVSS 9.8KEVWeaponizedEPSS 100%progress · moveit cloudJun 2, 2023
- CVE-2024-488599Now
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 99%progress · whatsup goldJun 25, 2024
- CVE-2024-121298Now
LoadMaster Pre-Authenticated OS Command Injection
CriticalCVSS 9.8KEVWeaponizedEPSS 95%progress · loadmasterFeb 21, 2024
- CVE-2024-667097Now
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 93%progress · whatsup goldAug 29, 2024
- CVE-2023-4004492Now
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 91%progress · ws ftp serverSep 27, 2023
- CVE-2017-1135792Now
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke
CriticalCVSS 9.8KEVWeaponizedEPSS 78%progress · telerik ui for asp.net ajaxAug 23, 2017
- CVE-2026-803792Now
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
CriticalCVSS 9.8KEVWeaponizedEPSS 77%progress · connection manager for objectscaleJun 4, 2026
- CVE-2017-924892Now
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te
CriticalCVSS 9.8KEVWeaponizedEPSS 75%progress · sitefinityJul 3, 2017
- CVE-2023-3570868This week
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL
CriticalCVSS 9.8Proof of conceptEPSS 97%progress · moveit transferJun 16, 2023
- CVE-2024-238967This week
Flowmon Unauthenticated Command Injection Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 93%progress · flowmonApr 2, 2024
- CVE-2023-3693465This week
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023
CriticalCVSS 9.1Proof of conceptEPSS 95%progress · moveit transferJul 5, 2023
- CVE-2024-580663This week
MOVEit Transfer Authentication Bypass Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 81%progress · moveit transferJun 25, 2024
- CVE-2024-488358Plan
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 65%progress · whatsup goldJun 25, 2024
- CVE-2023-3693256Plan
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023
HighCVSS 8.1No exploitEPSS 81%progress · moveit transferJul 5, 2023
- CVE-2003-077255Plan
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary cod
HighCVSS 7.5Proof of conceptEPSS 85%ipswitch · ws ftp serverSep 22, 2003
- CVE-2024-4690954Plan
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 49%progress · whatsup goldDec 2, 2024
- CVE-2006-484752Plan
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long
MediumCVSS 6.5WeaponizedEPSS 85%ipswitch · ws ftp serverSep 18, 2006
- CVE-2023-3693352Plan
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is
HighCVSS 7.5No exploitEPSS 72%progress · moveit transferJul 5, 2023
- CVE-2024-244852Plan
LoadMaster Command Injection Vulnerability
HighCVSS 8.8No exploitEPSS 55%progress · loadmasterMar 22, 2024
- CVE-2024-501051Plan
WhatsUp Gold TestController multiple information disclosure vulnerabilities
HighCVSS 7.5No exploitEPSS 70%progress · whatsup goldJun 25, 2024
- CVE-2004-079849Plan
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary co
HighCVSS 7.5WeaponizedEPSS 63%progress · whatsup goldOct 20, 2004
- CVE-2022-2984747Plan
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transac
HighCVSS 7.5WeaponizedEPSS 58%progress · whatsup goldMay 11, 2022
- CVE-2024-180047Plan
Progress Telerik Report Server Deserialization
HighCVSS 8.8WeaponizedEPSS 40%progress · telerik report serverMar 20, 2024
- CVE-2024-4690647Plan
WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability
HighCVSS 8.8No exploitEPSS 40%progress · whatsup goldDec 2, 2024
- CVE-2024-488446Plan
WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 24%progress · whatsup goldJun 25, 2024