Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hybrid Data Pipeline HIGH 8.1
CVE-2025-6505

Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vu…

Fix: 4.6.2.3275+
Fix from $1,950 2025-07-29
Telerik Ui For Asp.net Ajax HIGH 7.5
CVE-2025-3600EPSS 24%

In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled excepti…

Fix: after 2025.1.218
Fix from $1,950 2025-05-14
Whatsup Gold MEDIUM 5.3
CVE-2025-2572

In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the content…

Fix: 24.0.3+
Fix from $1,600 2025-04-14
Moveit Transfer HIGH 8.8
CVE-2025-2324

Improper Privilege Management vulnerability for users configured as Shared Accounts in Progress MOVEit Transfer (SFTP module) allows Privilege Escala…

Fix: 2023.1.12 / 2024.0.8+
Fix from $1,950 2025-03-19
Multi Tenant Loadmaster HIGH 8.8
CVE-2025-1758

Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: …

Fix: 7.2.61.1+
Fix from $1,950 2025-03-19
Telerik Reporting MEDIUM 5.3
CVE-2024-6097

In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolu…

Fix: 19.0.25.211+
Fix from $1,600 2025-02-12
Kendo Ui For Vue HIGH 7.2
CVE-2024-11628

In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype cha…

Fix: 6.1.0+
Fix from $1,950 2025-02-12
Telerik Document Processing Libraries MEDIUM 6.5
CVE-2024-11629

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an ar…

Fix: 2025.1.205+
Fix from $1,600 2025-02-12
Telerik Report Server MEDIUM 6.5
CVE-2025-0556

In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non…

Fix: 11.0.25.211+
Fix from $1,600 2025-02-12
Telerik Ui For Winforms CRITICAL 9.8
CVE-2025-0332

In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressi…

Fix: 2025.1.211+
Fix from $2,300 2025-02-12
Telerik Document Processing Libraries HIGH 8.8
CVE-2024-11343

In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system a…

Fix: 2025.1.205+
Fix from $1,950 2025-02-12
Kendoreact HIGH 7.2
CVE-2024-12629

In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain whi…

Fix: 9.4.0+
Fix from $1,950 2025-02-12
Telerik Ui For Winui HIGH 7.8
CVE-2024-12251

In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperli…

Fix: 3.0.0+
Fix from $1,950 2025-02-12
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-56134

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product …

Fix: 7.1.35.13 / 7.2.54.13+
Fix from $1,600 2025-02-05
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-56135

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product …

Fix: 7.1.35.13 / 7.2.54.13+
Fix from $1,600 2025-02-05
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-56131EPSS 6%

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product …

Fix: 7.1.35.13 / 7.2.54.13+
Fix from $1,600 2025-02-05
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-56132EPSS 6%

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product …

Fix: 7.1.35.13 / 7.2.54.13+
Fix from $1,600 2025-02-05
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-56133

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects:  Product …

Fix: 7.1.35.13 / 7.2.54.13+
Fix from $1,600 2025-02-05
Sitefinity HIGH 8.1
CVE-2024-11627

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4…

Fix: 14.4.8143 / 15.0.8230+
Fix from $1,950 2025-01-07
Sitefinity MEDIUM 5.3
CVE-2024-11625

Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 throu…

Fix: 14.4.8143 / 15.0.8230+
Fix from $1,600 2025-01-07
Whatsup Gold CRITICAL 9.6
CVE-2024-12108EPSS 7%

In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.

Fix: 24.0.2+
Fix from $2,300 2024-12-31
Whatsup Gold HIGH 7.5
CVE-2024-12106EPSS 10%

In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.

Fix: 24.0.2+
Fix from $1,950 2024-12-31
Whatsup Gold MEDIUM 6.5
CVE-2024-12105EPSS 42%

In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclo…

Fix: 24.0.2+
Fix from $1,600 2024-12-31
Whatsup Gold CRITICAL 9.8
CVE-2024-46909EPSS 49%

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context…

Fix: 24.0.1+
Fix from $2,300 2024-12-02
Whatsup Gold MEDIUM 5.3
CVE-2024-8785EPSS 10%

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registr…

Fix: 24.0.1+
Fix from $1,600 2024-12-02
Whatsup Gold HIGH 8.8
CVE-2024-46905

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Mana…

Fix: 24.0.1+
Fix from $1,950 2024-12-02
Whatsup Gold HIGH 8.8
CVE-2024-46906EPSS 41%

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer …

Fix: 24.0.1+
Fix from $1,950 2024-12-02
Whatsup Gold HIGH 8.8
CVE-2024-46907

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer …

Fix: 24.0.1+
Fix from $1,950 2024-12-02
Whatsup Gold HIGH 8.8
CVE-2024-46908

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer …

Fix: 24.0.1+
Fix from $1,950 2024-12-02
Telerik Document Processing Libraries MEDIUM 6.5
CVE-2024-8049

In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead t…

Fix: 2024.4.1106+
Fix from $1,600 2024-11-13