Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ws Ftp Server MEDIUM 6.1
CVE-2024-1474

In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Serv…

Fix: 8.8.5+
Fix from $1,600 2024-02-21
Telerik Reporting HIGH 7.8
CVE-2024-0832

In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In …

Fix: 18.0.24.130+
Fix from $1,950 2024-01-31
Telerik Test Studio HIGH 7.8
CVE-2024-0833

In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer compon…

Fix: 2023.3.1330+
Fix from $1,950 2024-01-31
Telerik Justdecompile HIGH 7.8
CVE-2024-0219

In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. …

Fix: after 2019.1.118.0
Fix from $1,950 2024-01-31
Openedge CRITICAL 9.9
CVE-2023-40051

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…

Fix: 11.7.18 / 12.2.13+
Fix from $2,300 2024-01-18
Openedge HIGH 7.5
CVE-2023-40052

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases p…

Fix: 11.7.18 / 12.2.13+
Fix from $1,950 2024-01-18
Moveit Transfer HIGH 7.1
CVE-2024-0396

In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validat…

Fix: 2022.0.10 / 2022.1.11+
Fix from $1,950 2024-01-17
Whatsup Gold MEDIUM 5.3
CVE-2023-6368

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthent…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Whatsup Gold MEDIUM 5.3
CVE-2023-6595

In WhatsUp Gold versions released before 2023.1, an API endpoint was found to be missing an authentication mechanism. It is possible for an unauthent…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Whatsup Gold MEDIUM 5.4
CVE-2023-6365

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attack…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Whatsup Gold MEDIUM 5.4
CVE-2023-6366

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attack…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Whatsup Gold MEDIUM 5.4
CVE-2023-6367

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified. It is possible for an attack…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Whatsup Gold MEDIUM 5.4
CVE-2023-6364

In WhatsUp Gold versions released before 2023.1, a stored cross-site scripting (XSS) vulnerability has been identified.  It is possible for an attack…

Fix: 23.1.0+
Fix from $1,600 2023-12-14
Moveit Transfer HIGH 7.2
CVE-2023-6218

In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a privilege escalation path associate…

Fix: 2022.0.9 / 2022.1.10+
Fix from $1,950 2023-11-29
Moveit Transfer MEDIUM 6.1
CVE-2023-6217

In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10), 2023.0.7 (15.0.7), a reflected cross-site scripting (XSS…

Fix: 2022.0.9 / 2022.1.10+
Fix from $1,600 2023-11-29
Ws Ftp Server HIGH 8.8
CVE-2023-42659

In WS_FTP Server versions prior to 8.7.6 and 8.8.4, an unrestricted file upload flaw has been identified. An authenticated Ad Hoc Transfer user has …

Fix: 8.7.6 / 8.8.4+
Fix from $1,950 2023-11-07
Ws Ftp Server CRITICAL 9.6
CVE-2023-42657EPSS 17%

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker could leverage this vulnerabilit…

Fix: 8.7.4 / 8.8.2+
Fix from $2,300 2023-09-27
Ws Ftp Server MEDIUM 5.3
CVE-2023-40049

In WS_FTP Server version prior to 8.8.2, an unauthenticated user could enumerate files under the 'WebServiceHost' directory listing.

Fix: 8.8.2+
Fix from $1,600 2023-09-27
Ws Ftp Server MEDIUM 6.5
CVE-2023-40048

In WS_FTP Server version prior to 8.8.2, the WS_FTP Server Manager interface was missing cross-site request forgery (CSRF) protection on a POST tra…

Fix: 8.8.2+
Fix from $1,600 2023-09-27
Ws Ftp Server HIGH 7.2
CVE-2023-40046

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a SQL injection vulnerability exists in the WS_FTP Server manager interface. An attacker may be…

Fix: 8.7.4 / 8.8.2+
Fix from $1,950 2023-09-27
Ws Ftp Server HIGH 8.8
CVE-2023-40044 KEVEPSS 90%

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Tr…

Fix: 8.7.4 / 8.8.2+
Fix from $1,950 2023-09-27
Ws Ftp Server MEDIUM 6.1
CVE-2023-40045

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a reflected cross-site scripting (XSS) vulnerability exists in WS_FTP Server's Ad Hoc Transfer …

Fix: 8.7.4 / 8.8.2+
Fix from $1,600 2023-09-27
Moveit Transfer HIGH 8.8
CVE-2023-42660

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vuln…

Fix: 2021.1.8 / 2022.0.8+
Fix from $1,950 2023-09-20
Moveit Transfer HIGH 7.2
CVE-2023-40043

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a SQL injection vuln…

Fix: 2021.1.8 / 2022.0.8+
Fix from $1,950 2023-09-20
Moveit Transfer MEDIUM 6.1
CVE-2023-42656

In Progress MOVEit Transfer versions released before 2021.1.8 (13.1.8), 2022.0.8 (14.0.8), 2022.1.9 (14.1.9), 2023.0.6 (15.0.6), a reflected cross-si…

Fix: 2021.1.8 / 2022.0.8+
Fix from $1,600 2023-09-20
Chef Infra Server MEDIUM 5.5
CVE-2023-28864

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup …

Fix: 15.7.0+
Fix from $1,600 2023-07-17
Moveit Transfer CRITICAL 9.1
CVE-2023-36934EPSS 95%

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.…

Fix: 12.1.11 / 13.0.9+
Fix from $2,300 2023-07-05
Moveit Transfer HIGH 8.1
CVE-2023-36932EPSS 81%

In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.…

Fix: 2020.1.11 / 2021.0.9+
Fix from $1,950 2023-07-05
Moveit Transfer HIGH 7.5
CVE-2023-36933EPSS 72%

In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible …

Fix: 2020.1.11 / 2021.0.9+
Fix from $1,950 2023-07-05
Openedge HIGH 8.8
CVE-2023-34203

In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a U…

Fix: 11.7.16 / 12.2.12+
Fix from $1,950 2023-06-23