Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Moveit Gateway CRITICAL 9.1
CVE-2024-5805EPSS 8%

Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.…

Mitigation only
Fix from $2,300 2024-06-25
Ws Ftp Server MEDIUM 6.1
CVE-2022-27665EPSS 33%

Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious cod…

No fix yet
Fix from $1,600 2023-04-03
Whatsup Gold MEDIUM 6.5
CVE-2022-29845

In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would…

Mitigation only
Fix from $1,600 2022-05-11
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2021-28141

An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web…

No fix yet
Fix from $2,300 2021-03-11
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2019-19790

Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICO…

Mitigation only
Fix from $2,300 2019-12-13
Fiddler HIGH 7.8
CVE-2019-12097

Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privile…

Mitigation only
Fix from $1,950 2019-06-03
Telerik Extensions For Asp.net Mvc MEDIUM 5.3
CVE-2018-17060

Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's …

Mitigation only
Fix from $1,600 2018-10-08
Kendo Ui MEDIUM 6.1
CVE-2018-14037

Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM …

No fix yet
Fix from $1,600 2018-09-28
Sitefinity HIGH 8.8
CVE-2017-18179

Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina…

No fix yet
Fix from $1,950 2018-02-12
Sitefinity MEDIUM 6.1
CVE-2017-18178

Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the tar…

No fix yet
Fix from $1,600 2018-02-12
Sitefinity MEDIUM 5.4
CVE-2017-18175

Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute o…

No fix yet
Fix from $1,600 2018-02-12
Sitefinity MEDIUM 5.4
CVE-2017-18176

Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is f…

No fix yet
Fix from $1,600 2018-02-12
Sitefinity MEDIUM 5.4
CVE-2017-18177

Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.

No fix yet
Fix from $1,600 2018-02-12
Sitefinity CRITICAL 9.8
CVE-2017-15883

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic…

Mitigation only
Fix from $2,300 2018-01-08
Openedge CRITICAL 9.8
CVE-2015-9245

Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…

Mitigation only
Fix from $2,300 2017-10-31
Whatsup Gold CRITICAL 9.8
CVE-2015-8261

The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows re…

No fix yet
Fix from $2,300 2016-01-08
Openedge MEDIUM 5.0
CVE-2014-8555EPSS 7%

Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read arbitrary files v…

No fix yet
Fix from $1,600 2014-11-12
Whatsup Gold HIGH 7.5
CVE-2012-2601

SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the …

No fix yet
Fix from $1,950 2012-08-15
Ws Ftp Server HIGH 9.0
CVE-2008-0590EPSS 22%

Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execut…

No fix yet
Fix from $1,950 2008-02-05
Openedge HIGH 7.5
CVE-2007-3491

Buffer overflow in _mprosrv in Progress Software OpenEdge before 9.1E0422, and 10.x before 10.1B01, allows remote attackers to have an unknown impact…

Mitigation only
Fix from $1,950 2007-06-29
Whatsup Gold HIGH 7.8
CVE-2007-2602

Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary co…

Mitigation only
Fix from $1,950 2007-05-11
Webspeed Messenger HIGH 7.8
CVE-2007-2354

Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", …

Mitigation only
Fix from $1,950 2007-04-30
Webspeed Messenger HIGH 10.0
CVE-2007-2266

Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WServi…

No fix yet
Fix from $1,950 2007-04-25
Whatsup Gold HIGH 7.5
CVE-2004-0798EPSS 63%

Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a …

No fix yet
Fix from $1,950 2004-10-20
Webspeed HIGH 7.5
CVE-2000-0127

The Webspeed configuration program does not properly disable access to the WSMadmin utility, which allows remote attackers to gain privileges via wsi…

Mitigation only
Fix from $1,950 2000-02-03