Where
-Infinity
0

Vendor Risk Score

See how progress compares to other vendors in security performance

View Risk Score →

Software

progress whatsup gold
29
progress software whatsup gold
28
progress moveit transfer
25
progress telerik ui for asp.net ajax
18
progress
16
progress kemp loadmaster
15
progress loadmaster
15
progress ws ftp server
15
progress ipswitch ws ftp server
13
progress software ws_ftp
13
progress ecs connection manager
12
progress software moveit transfer
12
progress connection manager for objectscale
11
progress moveit waf
10
progress object scale connection manager
9
progress openedge explorer
9
progress enterprise cloud services (ecs)
8
progress flowmon
7
progress marklogic server
7
progress moveit automation
7
progress moveit web application firewall
7
progress sitefinity
7
progress multi-tenant hypervisor
6
progress software moveit automation
6
progress telerik reporting
6
progress progress
5
progress software sitefinity
5
progress flowmon ads
4
progress openedge
4
progress sharefile storage zones controller
4
progress sharefile
3
progress datadirect odbc oracle wire protocol driver
2
progress flowmon anomaly detection system
2
progress hybrid data pipeline
2
progress openedge adminserver
2
progress openedge innovation
2
progress sharefile storage zones controller (szc)
2
progress telerik report server
2
progress telerik ui
2
progress telerik ui for ajax
2
progress telerik ui for winforms
2
progress webspeed
2
progress webspeed messenger
2
progress 4gl compiler
1
progress adminserver
1
progress asp.net ajax and sitefinity
1
progress connection manager for objectscale*
1
progress database
1
progress datadirect connect for jdbc autonomous rest connector
1
progress datadirect connect for jdbc for amazon redshift
1
Command Injection, OS Command Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

1 / 2
Source: CISA
First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been identified.  The vulnerability is a bypass to authentication based on a failure to properly handle username and password. Certain unexpected content passed into the credentials can lead to unauthorized access without proper authentication.

First published (updated )
Severity
10
OS Command Injection, Command Injection
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

First published (updated )
Severity
10
AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight and non-default site configuration.

First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In WSFTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WSFTP Server operating system.

1 / 2
Source: NVD
First published (updated )
Severity
10
Buffer Overflow
AV:N/AC:L/Au:N/C:C/I:C/A:C

Heap-based buffer overflow in mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute arbitrary code via crafted packets. NOTE: this issue might overlap CVE-2007-3491.

First published (updated )
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.

First published (updated )
Severity
9.9
Malicious File Upload
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. An attacker can formulate a request for a WEB transport that allows unintended file uploads to a server directory path on the system running PASOE. If the upload contains a payload that can further exploit the server or its network, the launch of a larger scale attack may be possible.

First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

First published (updated )
Severity
9.9
EPSS
0.07%
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.

First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database.

First published (updated )
Severity
9.9
EPSS
0.26%
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.

First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.

First published (updated )
Severity
9.9
Path Traversal
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

In WSFTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WSFTP folder path.  Attackers could also escape the context of the WSFTP Server file structure and perform the same level of operations (delete, rename, rmdir, mkdir) on file and folder locations on the underlying operating system.

First published (updated )
Severity
9.8
EPSS
93.84%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
EPSS
0.50%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.

First published (updated )
Severity
9.8
EPSS
8.63%
Command Injection, OS Command Injection, Code Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController

allows execution of commands with iisapppool\nmconsole privileges.

First published (updated )
Severity
9.8
EPSS
0.05%
Command Injection, OS Command Injection, Code Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.

First published (updated )
Severity
9.8
EPSS
94.31%
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The

WhatsUp.ExportUtilities.Export.GetFileWithoutZip

allows execution of commands with iisapppool\nmconsole privileges.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
EPSS
0.09%
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

First published (updated )
Severity
9.8
EPSS
0.04%
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.

First published (updated )
Severity
9.8
EPSS
0.05%
SQL Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
EPSS
0.04%
SQL Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

First published (updated )
Severity
9.8
EPSS
0.04%
Input Validation, Command Injection, OS Command Injection
AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:

Product

Affected Versions

LoadMaster

From 7.2.55.0 to 7.2.60.1 (inclusive)

From 7.2.49.0 to 7.2.54.12 (inclusive)

7.2.48.12 and all prior versions

Multi-Tenant Hypervisor

7.1.35.12 and all prior versions

ECS

All prior versions to 7.2.60.1 (inclusive)

1 / 2
Source: MITRE
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2024.0.0,

an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

First published (updated )
Severity
9.8
EPSS
0.05%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEYLOCALMACHINE\SOFTWARE\WOW6432Node\Ipswitch\.

First published (updated )
Severity
9.8
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

First published (updated )
Severity
9.8
Path Traversal
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.

First published (updated )
Severity
9.8
Input Validation, Malicious File Upload
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

1 / 2
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203