Записи Progress
301 опубликованных записей вендора progress.
Профиль для исследователя
- Попали в KEV
- 8 · 2,7 %
- С эксплойтом
- 17 · 5,6 %
- Pre-auth RCE
- 37
- С записью об исправлении
- 41,2 %
- Медиана: публикация → KEV
- 158 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')40
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')27
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')19
- CWE-20 Improper Input Validation13
- CWE-502 Deserialization of Untrusted Data12
- CWE-287 Improper Authentication11
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
301 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-34362Готовый эксплойт | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL progress · moveit cloud · CWE-89 | Критическая9,8 | KEV | 99,9 % | 2 июн. 2023 г. |
99Срочно | CVE-2024-4885Готовый эксплойт | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-22 | Критическая9,8 | KEV | 99,3 % | 25 июн. 2024 г. |
98Срочно | CVE-2024-1212Готовый эксплойт | LoadMaster Pre-Authenticated OS Command Injectionprogress · loadmaster · CWE-78 | Критическая9,8 | KEV | 95,4 % | 21 февр. 2024 г. |
97Срочно | CVE-2024-6670Готовый эксплойт | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-89 | Критическая9,8 | KEV | 93,0 % | 29 авг. 2024 г. |
92Срочно | CVE-2023-40044Готовый эксплойт | WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerabilityprogress · ws ftp server · CWE-502 | Высокая8,8 | KEV | 90,6 % | 27 сент. 2023 г. |
92Срочно | CVE-2017-11357Готовый эксплойт | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackeprogress · telerik ui for asp.net ajax · CWE-434 | Критическая9,8 | KEV | 77,7 % | 23 авг. 2017 г. |
92Срочно | CVE-2026-8037Готовый эксплойт | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFprogress · connection manager for objectscale · CWE-77 | Критическая9,8 | KEV | 77,4 % | 4 июн. 2026 г. |
92Срочно | CVE-2017-9248Готовый эксплойт | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Teprogress · sitefinity · CWE-522 | Критическая9,8 | KEV | 75,1 % | 3 июл. 2017 г. |
68На этой неделе | CVE-2023-35708Proof of concept | In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL progress · moveit transfer · CWE-89 | Критическая9,8 | — | 96,7 % | 16 июн. 2023 г. |
67На этой неделе | CVE-2024-2389Готовый эксплойт | Flowmon Unauthenticated Command Injection Vulnerabilityprogress · flowmon · CWE-78 | Критическая9,8 | — | 93,0 % | 2 апр. 2024 г. |
65На этой неделе | CVE-2023-36934Proof of concept | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023progress · moveit transfer · CWE-89 | Критическая9,1 | — | 95,2 % | 5 июл. 2023 г. |
63На этой неделе | CVE-2024-5806Готовый эксплойт | MOVEit Transfer Authentication Bypass Vulnerabilityprogress · moveit transfer · CWE-287 | Критическая9,8 | — | 81,5 % | 25 июн. 2024 г. |
58В плане | CVE-2024-4883Proof of concept | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-77 | Критическая9,8 | — | 64,5 % | 25 июн. 2024 г. |
56В плане | CVE-2023-36932Эксплойта нет | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023progress · moveit transfer · CWE-89 | Высокая8,1 | — | 81,1 % | 5 июл. 2023 г. |
55В плане | CVE-2003-0772Proof of concept | Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary codipswitch · ws ftp server | Высокая7,5 | — | 84,9 % | 22 сент. 2003 г. |
54В плане | CVE-2024-46909Эксплойта нет | WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-16 | Критическая9,8 | — | 48,9 % | 2 дек. 2024 г. |
52В плане | CVE-2006-4847Готовый эксплойт | Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via longipswitch · ws ftp server | Средняя6,5 | — | 85,3 % | 18 сент. 2006 г. |
52В плане | CVE-2023-36933Эксплойта нет | In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is progress · moveit transfer · CWE-755 | Высокая7,5 | — | 72,2 % | 5 июл. 2023 г. |
52В плане | CVE-2024-2448Эксплойта нет | LoadMaster Command Injection Vulnerabilityprogress · loadmaster · CWE-78 | Высокая8,8 | — | 55,4 % | 22 мар. 2024 г. |
51В плане | CVE-2024-5010Эксплойта нет | WhatsUp Gold TestController multiple information disclosure vulnerabilitiesprogress · whatsup gold · CWE-200 | Высокая7,5 | — | 70,0 % | 25 июн. 2024 г. |
49В плане | CVE-2004-0798Готовый эксплойт | Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary coprogress · whatsup gold | Высокая7,5 | — | 62,6 % | 20 окт. 2004 г. |
47В плане | CVE-2022-29847Готовый эксплойт | In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transacprogress · whatsup gold · CWE-918 | Высокая7,5 | — | 57,6 % | 11 мая 2022 г. |
47В плане | CVE-2024-1800Готовый эксплойт | Progress Telerik Report Server Deserializationprogress · telerik report server · CWE-502 | Высокая8,8 | — | 40,4 % | 20 мар. 2024 г. |
47В плане | CVE-2024-46906Эксплойта нет | WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerabilityprogress · whatsup gold · CWE-89 | Высокая8,8 | — | 40,4 % | 2 дек. 2024 г. |
46В плане | CVE-2024-4884Эксплойта нет | WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-77 | Критическая9,8 | — | 24,3 % | 25 июн. 2024 г. |
- CVE-2023-3436299Срочно
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %progress · moveit cloud2 июн. 2023 г.
- CVE-2024-488599Срочно
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %progress · whatsup gold25 июн. 2024 г.
- CVE-2024-121298Срочно
LoadMaster Pre-Authenticated OS Command Injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %progress · loadmaster21 февр. 2024 г.
- CVE-2024-667097Срочно
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %progress · whatsup gold29 авг. 2024 г.
- CVE-2023-4004492Срочно
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 91 %progress · ws ftp server27 сент. 2023 г.
- CVE-2017-1135792Срочно
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attacke
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 78 %progress · telerik ui for asp.net ajax23 авг. 2017 г.
- CVE-2026-803792Срочно
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 77 %progress · connection manager for objectscale4 июн. 2026 г.
- CVE-2017-924892Срочно
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Te
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 75 %progress · sitefinity3 июл. 2017 г.
- CVE-2023-3570868На этой неделе
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL
КритическаяCVSS 9,8Proof of conceptEPSS 97 %progress · moveit transfer16 июн. 2023 г.
- CVE-2024-238967На этой неделе
Flowmon Unauthenticated Command Injection Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 93 %progress · flowmon2 апр. 2024 г.
- CVE-2023-3693465На этой неделе
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023
КритическаяCVSS 9,1Proof of conceptEPSS 95 %progress · moveit transfer5 июл. 2023 г.
- CVE-2024-580663На этой неделе
MOVEit Transfer Authentication Bypass Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 81 %progress · moveit transfer25 июн. 2024 г.
- CVE-2024-488358В плане
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 65 %progress · whatsup gold25 июн. 2024 г.
- CVE-2023-3693256В плане
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023
ВысокаяCVSS 8,1Эксплойта нетEPSS 81 %progress · moveit transfer5 июл. 2023 г.
- CVE-2003-077255В плане
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary cod
ВысокаяCVSS 7,5Proof of conceptEPSS 85 %ipswitch · ws ftp server22 сент. 2003 г.
- CVE-2024-4690954В плане
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 49 %progress · whatsup gold2 дек. 2024 г.
- CVE-2006-484752В плане
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long
СредняяCVSS 6,5Готовый эксплойтEPSS 85 %ipswitch · ws ftp server18 сент. 2006 г.
- CVE-2023-3693352В плане
In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is
ВысокаяCVSS 7,5Эксплойта нетEPSS 72 %progress · moveit transfer5 июл. 2023 г.
- CVE-2024-244852В плане
LoadMaster Command Injection Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 55 %progress · loadmaster22 мар. 2024 г.
- CVE-2024-501051В плане
WhatsUp Gold TestController multiple information disclosure vulnerabilities
ВысокаяCVSS 7,5Эксплойта нетEPSS 70 %progress · whatsup gold25 июн. 2024 г.
- CVE-2004-079849В плане
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary co
ВысокаяCVSS 7,5Готовый эксплойтEPSS 63 %progress · whatsup gold20 окт. 2004 г.
- CVE-2022-2984747В плане
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transac
ВысокаяCVSS 7,5Готовый эксплойтEPSS 58 %progress · whatsup gold11 мая 2022 г.
- CVE-2024-180047В плане
Progress Telerik Report Server Deserialization
ВысокаяCVSS 8,8Готовый эксплойтEPSS 40 %progress · telerik report server20 мар. 2024 г.
- CVE-2024-4690647В плане
WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 40 %progress · whatsup gold2 дек. 2024 г.
- CVE-2024-488446В плане
WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 24 %progress · whatsup gold25 июн. 2024 г.