Filtered by vendor Progress
Subscribe
Total
301 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-11903 | 1 Progress | 1 Moveit Transfer | 2026-07-10 | N/A | 8.0 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. | |||||
| CVE-2026-8650 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 4.5 MEDIUM |
| Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-8651 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 3.7 LOW |
| Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-8800 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 2.7 LOW |
| Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-8801 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 3.5 LOW |
| Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. | |||||
| CVE-2026-9272 | 1 Progress | 1 Flowmon Anomaly Detection System | 2026-07-07 | N/A | 8.1 HIGH |
| In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification. | |||||
| CVE-2026-8079 | 1 Progress | 1 Flowmon | 2026-07-06 | N/A | 7.3 HIGH |
| In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration. | |||||
| CVE-2026-2737 | 1 Progress | 1 Flowmon | 2026-07-06 | N/A | 6.1 MEDIUM |
| A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |||||
| CVE-2026-3692 | 1 Progress | 1 Flowmon | 2026-07-06 | N/A | 8.8 HIGH |
| In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server. | |||||
| CVE-2026-6023 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-06-17 | N/A | 8.1 HIGH |
| In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible. | |||||
| CVE-2026-6022 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-06-17 | N/A | 7.5 HIGH |
| In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion. | |||||
| CVE-2026-5174 | 1 Progress | 1 Moveit Automation | 2026-06-17 | N/A | 7.7 HIGH |
| Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |||||
| CVE-2026-4670 | 1 Progress | 1 Moveit Automation | 2026-06-17 | N/A | 9.8 CRITICAL |
| Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |||||
| CVE-2026-4048 | 1 Progress | 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster | 2026-06-17 | N/A | 8.4 HIGH |
| OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process. | |||||
| CVE-2026-3519 | 1 Progress | 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster | 2026-06-17 | N/A | 8.4 HIGH |
| OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command | |||||
| CVE-2026-3518 | 1 Progress | 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster | 2026-06-17 | N/A | 8.4 HIGH |
| OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command | |||||
| CVE-2026-3517 | 1 Progress | 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster | 2026-06-17 | N/A | 8.4 HIGH |
| OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command | |||||
| CVE-2026-2878 | 1 Progress | 1 Telerik Ui For Asp.net Ajax | 2026-06-17 | N/A | 5.3 MEDIUM |
| In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering. | |||||
| CVE-2026-2701 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-06-17 | N/A | 9.1 CRITICAL |
| Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | |||||
| CVE-2026-2699 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-06-17 | N/A | 9.8 CRITICAL |
| Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. | |||||
