← Back

Progress

progress

258 CVEs • 47 products

Products (47)

Click to collapse
Toggle
Whatsup Gold
whatsup_gold
Ws Ftp Server
ws_ftp_server
Sitefinity
sitefinity
Loadmaster
loadmaster
Openedge
openedge
Progress
progress
Flowmon
flowmon
Webspeed
webspeed
Moveit Waf
moveit_waf
Database
database
4gl Compiler
4gl_compiler
Mixlib Archive
mixlib-archive
Kendo Ui
kendo_ui
Fiddler
fiddler
Whatsupgold
whatsupgold
Flowmon Os
flowmon_os
Moveit Cloud
moveit_cloud
Moveit Gateway
moveit_gateway
Kendoreact
kendoreact

CVEs (258)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Progress
Telerik
2Sitefinity
Ui For Asp.net Ajax
Apr 21, 2026
Jul 3, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it eas...Show more
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.Show less
1Progress
2Sitefinity Cms
Telerik Reporting
May 13, 2026
May 22, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary w...Show more
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.Show less
1Progress
1Whatsup Gold
May 6, 2026
Oct 6, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
1Progress
1Whatsup Gold
May 6, 2026
Jan 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP requ...Show more
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.Show less
1Progress
1Whatsup Gold
May 6, 2026
Dec 27, 2015
N/A· v4
6.9 MEDIUM· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap message, (3) the View Na...Show more
Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap message, (3) the View Names field, (4) the Group Names field, (5) the Flow Monitor Credentials field, (6) the Flow Monitor Threshold Name field, (7) the Task Library Name field, (8) the Task Library Description field, (9) the Policy Library Name field, (10) the Policy Library Description field, (11) the Template Library Name field, (12) the Template Library Description field, (13) the System Script Library Name field, (14) the System Script Library Description field, or (15) the CLI Settings Library Description field.Show less
1Progress
1Whatsup Gold
May 6, 2026
Dec 27, 2015
N/A· v4
6.5 MEDIUM· v3
6.5 MEDIUM· v2
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports com...Show more
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.Show less
1Progress
1Telerik Ui For Asp.net Ajax
May 6, 2026
Dec 25, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbit...Show more
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.Show less
1Progress
1Openedge
May 6, 2026
Nov 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the selection parameter.
1Progress
1Whatsup Gold
Apr 29, 2026
Aug 15, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the SNMP system name of the attacking host.
1Progress
1Whatsup Gold
Apr 29, 2026
Aug 15, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the sGroupList parameter.
1Progress
1Ws Ftp Server
Apr 23, 2026
Feb 5, 2008
N/A· v4
N/A· v3
9.0 HIGH· v2
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.
2Progress
Rsa
3Ace Server
OpenedgeProgress
Apr 23, 2026
Jul 15, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products,...Show more
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.Show less
1Progress
1Openedge
Apr 23, 2026
Jun 29, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact via a malformed TCP/IP message.
1Progress
1Whatsup Gold
Apr 23, 2026
May 11, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary code via a long MIB filename argument. NOTE: If there is not a common sc...Show more
Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary code via a long MIB filename argument. NOTE: If there is not a common scenario under which MIBEXTRA.EXE is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.Show less
1Progress
2Progress
Webspeed
Apr 23, 2026
May 4, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edi...Show more
WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attackers to cause a denial of service (infinite loop and daemon hang) via a messenger URL that invokes _edit.r with no additional parameters, as demonstrated by requests for cgiip.exe or wsisa.dll with WService=wsbroker1/_edit.r in the PATH_INFO.Show less
1Progress
1Webspeed Messenger
Apr 23, 2026
Apr 30, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", which reveals the operating system and product information.
1Progress
1Webspeed Messenger
Apr 23, 2026
Apr 25, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstr...Show more
Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.Show less
2Ipswitch
Progress
2Ws Ftp Server
Ws Ftp Server
Apr 16, 2026
Sep 26, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary t...Show more
Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue.Show less
2Ipswitch
Progress
2Ws Ftp Server
Ws Ftp Server
Apr 16, 2026
Sep 26, 2006
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. N...Show more
Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong issue.Show less
2Ipswitch
Progress
2Ws Ftp Server
Ws Ftp Server
Apr 16, 2026
Sep 19, 2006
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.