Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Telerik Report Server MEDIUM 6.2
CVE-2024-7295

In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may al…

Fix: 10.3.24.1112+
Fix from $1,600 2024-11-13
Telerik Ui For Winforms HIGH 7.8
CVE-2024-10013

In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization …

Fix: 2024.4.1113+
Fix from $1,950 2024-11-13
Whatsup Gold HIGH 7.5
CVE-2024-7763

In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credenti…

Fix: 24.0+
Fix from $1,950 2024-10-24
Loadmaster CRITICAL 9.8
CVE-2024-8755

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects:  Product …

Fix: 7.2.61.0+
Fix from $2,300 2024-10-11
Telerik Reporting HIGH 7.8
CVE-2024-8048

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expres…

Fix: 18.2.24.924+
Fix from $1,950 2024-10-09
Telerik Report Server HIGH 7.2
CVE-2024-8015

In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an…

Fix: 10.2.24.924+
Fix from $1,950 2024-10-09
Telerik Reporting HIGH 8.8
CVE-2024-7293

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requir…

Fix: 10.2.24.806+
Fix from $1,950 2024-10-09
Telerik Reporting HIGH 8.8
CVE-2024-8014

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure t…

Fix: 18.2.24.924+
Fix from $1,950 2024-10-09
Telerik Reporting HIGH 7.8
CVE-2024-7840

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hype…

Fix: after 18.2.24.924
Fix from $1,950 2024-10-09
Telerik Reporting MEDIUM 6.5
CVE-2024-7294

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limit…

Fix: 10.2.24.806+
Fix from $1,600 2024-10-09
Telerik Report Server HIGH 8.8
CVE-2024-7292

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of…

Fix: 10.2.24.806+
Fix from $1,950 2024-10-09
Multi Tenant Loadmaster MEDIUM 6.8
CVE-2024-6658

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects:  Product …

Fix: 7.1.35.12 / 7.2.54.12+
Fix from $1,600 2024-09-12
Openedge MEDIUM 6.1
CVE-2024-7654

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.…

Fix: 12.8.3+
Fix from $1,600 2024-09-03
Openedge CRITICAL 9.6
CVE-2024-7345

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents o…

Fix: after 12.2.13
Fix from $2,300 2024-09-03
Whatsup Gold CRITICAL 9.8
CVE-2024-6670 KEVEPSS 95%

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted p…

Fix: 24.0+
Fix from $2,300 2024-08-29
Whatsup Gold CRITICAL 9.8
CVE-2024-6671EPSS 15%

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an …

Fix: 24.0+
Fix from $2,300 2024-08-29
Whatsup Gold HIGH 8.8
CVE-2024-6672

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege…

Fix: 24.0+
Fix from $1,950 2024-08-29
Ws Ftp Server HIGH 8.1
CVE-2024-7745

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to …

Fix: 8.8.8+
Fix from $1,950 2024-08-28
Ws Ftp Server MEDIUM 6.5
CVE-2024-7744

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in…

Fix: 8.8.8+
Fix from $1,600 2024-08-28
Moveit Transfer CRITICAL 9.8
CVE-2024-6576

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: …

Fix: 2023.0.12 / 2023.1.7+
Fix from $2,300 2024-07-29
Telerik Reporting CRITICAL 9.8
CVE-2024-6096

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type reso…

Fix: 18.1.24.709+
Fix from $2,300 2024-07-24
Telerik Report Server CRITICAL 9.8
CVE-2024-6327

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deseriali…

Fix: 10.1.24.709+
Fix from $2,300 2024-07-24
Whatsup Gold HIGH 7.5
CVE-2024-5018

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionControl…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 7.5
CVE-2024-5019

In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionContr…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 7.2
CVE-2024-5016EPSS 22%

In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Re…

Fix: 23.1.0+
Fix from $1,950 2024-06-25
Whatsup Gold MEDIUM 6.5
CVE-2024-5017

In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProf…

Fix: 23.1.3+
Fix from $1,600 2024-06-25
Whatsup Gold HIGH 8.8
CVE-2024-5015

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 8.6
CVE-2024-5012

In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability a…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 7.5
CVE-2024-5013

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker c…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold MEDIUM 6.5
CVE-2024-5014

In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any au…

Fix: 23.1.3+
Fix from $1,600 2024-06-25