← Back

Progress

progress

301 CVEs • 49 products

Products (49)

Click to collapse
Toggle
Whatsup Gold
whatsup_gold
Ws Ftp Server
ws_ftp_server
Loadmaster
loadmaster
Sitefinity
sitefinity
Openedge
openedge
Progress
progress
Flowmon
flowmon
Webspeed
webspeed
Moveit Waf
moveit_waf
Database
database
4gl Compiler
4gl_compiler
Mixlib Archive
mixlib-archive
Kendo Ui
kendo_ui
Fiddler
fiddler
Whatsupgold
whatsupgold
Flowmon Os
flowmon_os
Moveit Cloud
moveit_cloud
Moveit Gateway
moveit_gateway
Kendoreact
kendoreact

CVEs (301)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary op...Show more
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary op...Show more
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise.Show less
1Progress
4Connection Manager For Objectscale*
Ecs Connection ManagerLoadmaster+1 more
Aug 11, 2026
Jul 27, 2026
N/A· v4
8.4 HIGH· v3
N/A· v2
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary op...Show more
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise.Show less
1Progress
1Moveit Transfer
Jul 30, 2026
Jul 23, 2026
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
1Progress
1Moveit Transfer
Jul 30, 2026
Jul 23, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
1Progress
1Moveit Transfer
Jul 30, 2026
Jul 23, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
1Progress
1Moveit Transfer
Jul 30, 2026
Jul 23, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application dir...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
5.3 MEDIUM· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary ho...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote cod...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger uninten...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
5.9 MEDIUM· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote co...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected meta...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.Show less
1Progress
1Telerik Ui For Asp.net Ajax
Aug 6, 2026
Jul 22, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affect...Show more
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.Show less