Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flowmon Anomaly Detection System HIGH 8.1
CVE-2026-9272

In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged use…

Fix: 12.5.6 / 13.0.5+
Fix from $1,950 2026-07-02
Flowmon HIGH 7.3
CVE-2026-8079

In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request dur…

Fix: 12.5.9 / 13.0.11+
Fix from $1,950 2026-07-02
Connection Manager For Objectscale CRITICAL 9.8
CVE-2026-8037 KEVEPSS 99%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com…

Fix: 7.2.54.18 / 7.2.63.2+
Fix from $2,300 2026-06-04
Sitefinity CRITICAL 9.8
CVE-2026-7198

CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access…

Fix: 15.4.8630+
Fix from $2,300 2026-06-02
Sitefinity HIGH 8.8
CVE-2026-7201

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, an…

Fix: 15.2.8441 / 15.3.8531+
Fix from $1,950 2026-06-02
Sitefinity HIGH 8.1
CVE-2026-7195

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.…

Fix: 14.4.8152 / 15.0.8234+
Fix from $1,950 2026-06-02
Sitefinity HIGH 7.5
CVE-2026-7312

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234,…

Fix: 14.4.8152 / 15.0.8234+
Fix from $1,950 2026-06-02
Moveit Automation HIGH 7.5
CVE-2026-8486

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Moveit Automation HIGH 7.5
CVE-2026-8487

Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEi…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Moveit Automation HIGH 7.5
CVE-2026-8488

Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue af…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Moveit Automation HIGH 7.5
CVE-2026-8485

Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automatio…

Fix: 2025.0.11 / 2025.1.7+
Fix from $1,950 2026-05-20
Moveit Automation CRITICAL 9.8
CVE-2026-4670EPSS 6%

Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVE…

Fix: 2024.1.8 / 2025.1.5+
Fix from $2,300 2026-04-30
Moveit Automation HIGH 8.8
CVE-2026-5174

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: fr…

Fix: 2024.1.8 / 2025.1.5+
Fix from $1,950 2026-04-30
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2026-6023

In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto…

Fix: 2026.1.421+
Fix from $2,300 2026-04-22
Telerik Ui For Asp.net Ajax HIGH 7.5
CVE-2026-6022

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file up…

Fix: 2026.1.421+
Fix from $1,950 2026-04-22
Connection Manager For Objectscale HIGH 7.2
CVE-2026-4048

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to ex…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Connection Manager For Objectscale HIGH 7.2
CVE-2026-3517EPSS 18%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” p…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Connection Manager For Objectscale HIGH 7.2
CVE-2026-3518EPSS 20%

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to e…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Connection Manager For Objectscale HIGH 7.2
CVE-2026-3519

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” pe…

Fix: 7.2.54.17 / 7.2.63.1+
Fix from $1,950 2026-04-20
Flowmon HIGH 8.8
CVE-2026-3692

In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the repo…

Fix: 12.5.8+
Fix from $1,950 2026-04-02
Flowmon MEDIUM 6.1
CVE-2026-2737

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an a…

Fix: 12.5.8 / 13.0.6+
Fix from $1,600 2026-04-02
Sharefile Storage Zones Controller CRITICAL 9.8
CVE-2026-2699EPSS 58%

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to …

Fix: 5.12.4+
Fix from $2,300 2026-04-02
Sharefile Storage Zones Controller HIGH 8.8
CVE-2026-2701EPSS 57%

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Fix: 5.12.4+
Fix from $1,950 2026-04-02
Telerik Ui For Asp.net Ajax MEDIUM 5.9
CVE-2026-2878

In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable …

Fix: 2026.1.225+
Fix from $1,600 2026-02-25
Connection Manager For Objectscale* MEDIUM 6.8
CVE-2025-13447EPSS 26%

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe…

Fix: 7.1.35.15 / 7.2.54.16+
Fix from $1,600 2026-01-13
Connection Manager For Objectscale MEDIUM 6.8
CVE-2025-13444EPSS 26%

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe…

Fix: 7.1.35.15 / 7.2.54.16+
Fix from $1,600 2026-01-13
Flowmon Anomaly Detection System HIGH 8.8
CVE-2025-13774

A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to…

Fix: after 13.0.1
Fix from $1,950 2026-01-13
Moveit Transfer HIGH 7.5
CVE-2025-11235

Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 …

Fix: 2022.0.10 / 2022.1.11+
Fix from $1,950 2026-01-07
Moveit Transfer MEDIUM 5.3
CVE-2025-13147

Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 befor…

Fix: 2024.1.8 / 2025.0.4+
Fix from $1,600 2025-11-19
Hybrid Data Pipeline HIGH 8.4
CVE-2025-6504

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a …

Fix: 4.6.2.2978+
Fix from $1,950 2025-07-29