Filtered by vendor Progress
Subscribe
Total
301 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65941 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 8.8 HIGH |
| In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | |||||
| CVE-2017-11357 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-14 | 7.5 HIGH | 9.8 CRITICAL |
| Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |||||
| CVE-2026-59686 | 1 Progress | 4 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 1 more | 2026-08-11 | N/A | 8.4 HIGH |
| An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially resulting in complete system compromise. | |||||
| CVE-2026-59687 | 1 Progress | 4 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 1 more | 2026-08-11 | N/A | 8.4 HIGH |
| An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface, potentially resulting in complete system compromise. | |||||
| CVE-2026-59688 | 1 Progress | 4 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 1 more | 2026-08-11 | N/A | 8.4 HIGH |
| An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially resulting in complete system compromise. | |||||
| CVE-2026-59689 | 1 Progress | 4 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 1 more | 2026-08-11 | N/A | 8.0 HIGH |
| An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |||||
| CVE-2026-59690 | 1 Progress | 5 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 2 more | 2026-08-11 | N/A | 8.0 HIGH |
| A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise. | |||||
| CVE-2025-13444 | 1 Progress | 5 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 2 more | 2026-08-10 | N/A | 8.4 HIGH |
| OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |||||
| CVE-2026-8037 | 1 Progress | 4 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster and 1 more | 2026-08-10 | N/A | 9.6 CRITICAL |
| OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |||||
| CVE-2026-13181 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 8.1 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments. | |||||
| CVE-2026-13182 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 7.5 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers. | |||||
| CVE-2026-13183 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 7.5 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values. | |||||
| CVE-2026-13184 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 7.5 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains. | |||||
| CVE-2026-13185 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 8.1 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. | |||||
| CVE-2026-13186 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 8.1 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. | |||||
| CVE-2026-13187 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 8.1 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation. | |||||
| CVE-2026-13188 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 5.9 MEDIUM |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation. | |||||
| CVE-2026-13189 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 7.5 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests. | |||||
| CVE-2026-13190 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 8.1 HIGH |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. | |||||
| CVE-2026-13192 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-08-06 | N/A | 6.5 MEDIUM |
| In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials. | |||||
