Progress
progress
301 CVEs • 49 products
Products (49)
Click to collapseToggle
Products (49)
Click to collapse
CVEs (301)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4. |
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sour...Show more |
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized ac...Show more |
1Progress 1Telerik Ui For Asp.net Ajax Jun 17, 2026 May 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service. |
In WhatsUp Gold versions released before 2024.0.3, a
database manipulation
vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. |
Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escalation.This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.12...Show more |
1Progress 2Loadmaster Multi Tenant LoadmasterJun 17, 2026 Mar 19, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects:
* LoadMaster: 7.2.40.0 and above
* ECS: All versions
* Multi-Tenancy: 7.1.35.4 and above |
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability. |
1Progress 1Telerik Document Processing Libraries Jun 17, 2026 Feb 12, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF. |
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. |
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host p...Show more |
1Progress 1Telerik Ui For Winforms Jun 17, 2026 Feb 12, 2025 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. |
In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. |
1Progress 1Telerik Document Processing Libraries Jun 17, 2026 Feb 12, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. |
2Progress Telerik2Telerik Ui For Winui Ui For WinuiJun 17, 2026 Feb 12, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements. |
1Progress 2Loadmaster Multi Tenant LoadmasterJun 17, 2026 Feb 5, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60....Show more |
1Progress 2Loadmaster Multi Tenant LoadmasterJun 17, 2026 Feb 5, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60....Show more |
1Progress 2Loadmaster Multi Tenant LoadmasterJun 17, 2026 Feb 5, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60....Show more |
1Progress 2Loadmaster Multi Tenant LoadmasterJun 17, 2026 Feb 5, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60....Show more |
1Progress 2Loadmaster Multi Tenant LoadmasterJun 17, 2026 Feb 5, 2025 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60....Show more |