Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Whatsup Gold HIGH 8.8
CVE-2024-5008EPSS 17%

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 8.4
CVE-2024-5009EPSS 15%

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword …

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 7.5
CVE-2024-5010EPSS 70%

In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specially crafted unauthenticated…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold HIGH 7.5
CVE-2024-5011EPSS 47%

In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTT…

Fix: 23.1.3+
Fix from $1,950 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4883EPSS 65%

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauth…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4884EPSS 24%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Whatsup Gold CRITICAL 9.8
CVE-2024-4885 KEVEPSS 99%

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.Exp…

Fix: 23.1.3+
Fix from $2,300 2024-06-25
Moveit Transfer CRITICAL 9.8
CVE-2024-5806EPSS 81%

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer:…

Fix: 2023.0.11 / 2023.1.6+
Fix from $2,300 2024-06-25
Moveit Gateway CRITICAL 9.1
CVE-2024-5805EPSS 8%

Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.…

Mitigation only
Fix from $2,300 2024-06-25
Sitefinity MEDIUM 5.4
CVE-2023-27636

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

Fix: 15.0.0+
Fix from $1,600 2024-06-16
Moveit Automation HIGH 7.5
CVE-2024-4563

The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.

Fix: 2024.0.0+
Fix from $1,950 2024-05-22
Telerik Report Server MEDIUM 5.3
CVE-2024-4837

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se…

Fix: 10.1.24.514+
Fix from $1,600 2024-05-15
Telerik Reporting HIGH 8.6
CVE-2024-4202

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulner…

Fix: 18.1.24.514+
Fix from $1,950 2024-05-15
Telerik Reporting HIGH 7.8
CVE-2024-4200

In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an ins…

Fix: 18.1.24.514+
Fix from $1,950 2024-05-15
Telerik Reporting MEDIUM 6.5
CVE-2024-4357

An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege atta…

Fix: 10.1.24.514+
Fix from $1,600 2024-05-15
Telerik Ui For Winforms MEDIUM 6.7
CVE-2024-3892

A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability cou…

Fix: 2024.2.514+
Fix from $1,600 2024-05-15
Whatsup Gold MEDIUM 5.4
CVE-2024-4562

In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functional…

Fix: 23.1.2+
Fix from $1,600 2024-05-14
Whatsup Gold MEDIUM 5.3
CVE-2024-4561

In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker t…

Fix: 23.1.2+
Fix from $1,600 2024-05-14
Loadmaster HIGH 7.5
CVE-2024-3544

Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to the same network of one of the …

Fix: 7.2.48.11 / 7.2.54.10+
Fix from $1,950 2024-05-02
Loadmaster HIGH 7.5
CVE-2024-3543

Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be easily unencrypted by the attack…

Fix: 7.2.54.10 / 7.2.59.4+
Fix from $1,950 2024-05-02
Flowmon CRITICAL 9.8
CVE-2024-2389EPSS 93%

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user ca…

Fix: 11.1.14 / 12.3.5+
Fix from $2,300 2024-04-02
Loadmaster HIGH 7.5
CVE-2024-2449EPSS 13%

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the I…

Fix: 7.2.54.9 / 7.2.59.3+
Fix from $1,950 2024-03-22
Loadmaster HIGH 8.8
CVE-2024-2448EPSS 55%

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject…

Fix: 7.2.54.9 / 7.2.59.3+
Fix from $1,950 2024-03-22
Telerik Reporting HIGH 8.8
CVE-2024-1856

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an inse…

Fix: 18.0.24.130+
Fix from $1,950 2024-03-20
Telerik Reporting HIGH 7.8
CVE-2024-1801

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insec…

Fix: 18.0.24.130+
Fix from $1,950 2024-03-20
Telerik Report Server HIGH 8.8
CVE-2024-1800EPSS 40%

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deseriali…

Fix: 10.0.24.130+
Fix from $1,950 2024-03-20
Sitefinity MEDIUM 5.4
CVE-2024-1636

Potential Cross-Site Scripting (XSS) in the page editing area.

Fix: 13.3.7649 / 14.4.8135+
Fix from $1,600 2024-02-28
Sitefinity MEDIUM 6.5
CVE-2024-1632

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

Fix: 13.3.7649 / 14.4.8135+
Fix from $1,600 2024-02-28
Openedge CRITICAL 9.8
CVE-2024-1403

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentic…

Fix: 11.7.19 / 12.2.14+
Fix from $2,300 2024-02-27
Loadmaster CRITICAL 9.8
CVE-2024-1212 KEVEPSS 95%

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Fix: 7.2.48.10 / 7.2.54.8+
Fix from $2,300 2024-02-21