Filtered by vendor Progress
Subscribe
Total
301 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-9203 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 8.5 HIGH |
| A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud instance metadata endpoints. Successful exploitation can disclose cloud credentials and compromise cloud resources accessible to the host instance. | |||||
| CVE-2026-9195 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.3 CRITICAL |
| A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture credentials, and perform privileged actions on the administrator's behalf. | |||||
| CVE-2026-9193 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.9 CRITICAL |
| An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database. | |||||
| CVE-2026-15724 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-09-03 | N/A | 8.7 HIGH |
| In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |||||
| CVE-2026-2514 | 1 Progress | 1 Flowmon Anomaly Detection System | 2026-09-03 | N/A | 6.1 MEDIUM |
| In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's browser context. | |||||
| CVE-2026-2513 | 1 Progress | 1 Flowmon Anomaly Detection System | 2026-09-03 | N/A | 6.1 MEDIUM |
| A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |||||
| CVE-2026-8709 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.9 CRITICAL |
| An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the Security database. | |||||
| CVE-2026-9190 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.1 CRITICAL |
| An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs when a crafted HTTP request containing both Content-Length and Transfer-Encoding headers causes a reverse proxy and MarkLogic Server to interpret request boundaries differently. | |||||
| CVE-2026-9192 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.8 CRITICAL |
| An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including administrators. | |||||
| CVE-2026-7326 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 7.5 HIGH |
| A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration. | |||||
| CVE-2026-7327 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 8.1 HIGH |
| An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user. | |||||
| CVE-2026-7329 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.9 CRITICAL |
| An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access. | |||||
| CVE-2026-7557 | 1 Progress | 1 Marklogic Server | 2026-09-03 | N/A | 9.1 CRITICAL |
| An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This vulnerability affects deployments with SAML single sign-on enabled. | |||||
| CVE-2026-16139 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-09-02 | N/A | 7.2 HIGH |
| In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrator can exploit improper validation in the download preparation flow, enabling attacker-controlled files to be written outside the intended preparation directory. This can lead to remote code execution in v5 versions. Remote code execution is not confirmed on v6 versions. | |||||
| CVE-2026-16138 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-09-02 | N/A | 8.0 HIGH |
| In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host. | |||||
| CVE-2026-16137 | 1 Progress | 1 Sharefile Storage Zones Controller | 2026-09-02 | N/A | 7.2 HIGH |
| In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code. | |||||
| CVE-2026-65937 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 8.0 HIGH |
| In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. | |||||
| CVE-2026-65938 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 4.3 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | |||||
| CVE-2026-65939 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 6.8 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | |||||
| CVE-2026-65940 | 1 Progress | 1 Whatsup Gold | 2026-09-02 | N/A | 6.8 MEDIUM |
| In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | |||||
