Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Whatsup Gold MEDIUM 6.1
CVE-2023-35759

In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unaut…

Fix: 23.0.0+
Fix from $1,600 2023-06-23
Moveit Transfer CRITICAL 9.8
CVE-2023-35708EPSS 97%

In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection…

Fix: 2020.1.10 / 2021.0.8+
Fix from $2,300 2023-06-16
Moveit Transfer CRITICAL 9.1
CVE-2023-35036EPSS 13%

In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection v…

Fix: 2021.0.7 / 2021.1.5+
Fix from $2,300 2023-06-12
Datadirect Odbc Oracle Wire Protocol Driver CRITICAL 9.8
CVE-2023-34364

A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a…

Fix: 08.02.2770+
Fix from $2,300 2023-06-09
Datadirect Odbc Oracle Wire Protocol Driver MEDIUM 5.9
CVE-2023-34363

An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, i…

Fix: 08.02.2770+
Fix from $1,600 2023-06-09
Moveit Cloud CRITICAL 9.8
CVE-2023-34362 KEVEPSS 100%

In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection…

Fix: 14.0.5.45 / 14.1.6.97+
Fix from $2,300 2023-06-02
Flowmon Packet Investigator HIGH 7.5
CVE-2023-26101

In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vuln…

Fix: 12.1.0+
Fix from $1,950 2023-04-21
Flowmon Os MEDIUM 6.1
CVE-2023-26100

In Progress Flowmon before 12.2.0, an application endpoint failed to sanitize user-supplied input. A threat actor could leverage a reflected XSS vuln…

Fix: 12.2.0+
Fix from $1,600 2023-04-21
Sitefinity CRITICAL 9.8
CVE-2023-29375

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 b…

Fix: 13.3.7646 / 14.0.7736+
Fix from $2,300 2023-04-10
Sitefinity MEDIUM 5.4
CVE-2023-29376

An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 b…

Fix: 13.3.7646 / 14.0.7736+
Fix from $1,600 2023-04-10
Ws Ftp Server MEDIUM 6.1
CVE-2022-27665EPSS 33%

Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious cod…

No fix yet
Fix from $1,600 2023-04-03
Ws Ftp Server HIGH 7.2
CVE-2023-24029

In Progress WS_FTP Server before 8.8, it is possible for a host administrator to elevate their privileges via the administrative interface due to ins…

Fix: 8.8+
Fix from $1,950 2023-02-03
Whatsup Gold CRITICAL 9.6
CVE-2022-42711

In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an un…

Fix: 22.1.0+
Fix from $2,300 2022-10-12
Ipswitch Ws Ftp Server MEDIUM 6.1
CVE-2022-36967

In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web inter…

Fix: 8.7.3+
Fix from $1,600 2022-08-02
Whatsup Gold HIGH 7.5
CVE-2022-29847EPSS 57%

In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that…

Fix: after 21.1.1
Fix from $1,950 2022-05-11
Whatsup Gold MEDIUM 6.5
CVE-2022-29845

In Progress Ipswitch WhatsUp Gold 21.1.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would…

Mitigation only
Fix from $1,600 2022-05-11
Whatsup Gold MEDIUM 6.5
CVE-2022-29848

In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would…

Fix: after 21.1.1
Fix from $1,600 2022-05-11
Whatsup Gold MEDIUM 5.3
CVE-2022-29846EPSS 5%

In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obtain the WhatsUp Gold installa…

Fix: after 21.1.1
Fix from $1,600 2022-05-11
Openedge HIGH 7.8
CVE-2022-29849

In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escal…

Fix: 11.7.14 / 12.2.9+
Fix from $1,950 2022-05-02
Whatsupgold MEDIUM 6.1
CVE-2021-41318EPSS 6%

In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input. which could allow an unauthe…

Fix: 21.1.0+
Fix from $1,600 2021-09-28
Moveit Transfer CRITICAL 9.8
CVE-2021-38159

In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauth…

Fix: 2019.0.8 / 2019.1.7+
Fix from $2,300 2021-08-07
Moveit Transfer HIGH 8.8
CVE-2021-37614

In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web application could allow an authen…

Fix: 2019.0.7 / 2019.1.6+
Fix from $1,950 2021-08-05
Moveit Transfer HIGH 8.8
CVE-2021-33894

In Progress MOVEit Transfer before 2019.0.6 (11.0.6), 2019.1.x before 2019.1.5 (11.1.5), 2019.2.x before 2019.2.2 (11.2.2), 2020.x before 2020.0.5 (1…

Fix: 2019.0.6 / 2019.1.5+
Fix from $1,950 2021-06-09
Moveit Transfer HIGH 8.8
CVE-2021-31827

In Progress MOVEit Transfer before 2021.0 (13.0), a SQL injection vulnerability has been found in the MOVEit Transfer web app that could allow an aut…

Fix: 2021.0+
Fix from $1,950 2021-05-18
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2021-28141

An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web…

No fix yet
Fix from $2,300 2021-03-11
Moveit Transfer MEDIUM 5.4
CVE-2020-28647

In Progress MOVEit Transfer before 2020.1, a malicious user could craft and store a payload within the application. If a victim within the MOVEit Tra…

Fix: 2020.1+
Fix from $1,600 2020-11-17
Moveit Automation MEDIUM 6.1
CVE-2020-12677

An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately sanitize malicious input, whic…

Fix: 2018.0.3 / 2018.2.3+
Fix from $1,600 2020-05-14
Loadmaster HIGH 8.8
CVE-2014-5287EPSS 8%

A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI…

Fix: after 7.1-16
Fix from $1,950 2020-01-08
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2019-19790

Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICO…

Mitigation only
Fix from $2,300 2019-12-13
Sitefinity CRITICAL 9.8
CVE-2019-17392

Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.

Fix: 9.1.6185 / 9.2.6276+
Fix from $2,300 2019-11-26