Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sitefinity Cms MEDIUM 6.1
CVE-2017-18639

Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : Lis…

Fix: 10.1+
Fix from $1,600 2019-11-06
Ws Ftp Server MEDIUM 5.3
CVE-2019-12143

A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string …

Fix: 8.6.1+
Fix from $1,600 2019-06-11
Sitefinity MEDIUM 6.5
CVE-2019-7215

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remai…

Fix: 7.0.5143 / 7.1.5243+
Fix from $1,600 2019-06-06
Fiddler HIGH 7.8
CVE-2019-12097

Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privile…

Mitigation only
Fix from $1,950 2019-06-03
Telerik Extensions For Asp.net Mvc MEDIUM 5.3
CVE-2018-17060

Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's …

Mitigation only
Fix from $1,600 2018-10-08
Sitefinity Cms MEDIUM 6.1
CVE-2018-17053

Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject a…

Fix: after 11.0
Fix from $1,600 2018-10-03
Sitefinity Cms MEDIUM 6.1
CVE-2018-17054

Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject a…

Fix: after 11.0
Fix from $1,600 2018-10-03
Sitefinity HIGH 7.5
CVE-2018-17055

An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.

Fix: after 11.0
Fix from $1,950 2018-09-28
Sitefinity Cms MEDIUM 6.1
CVE-2018-17056

Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbi…

Fix: after 11.0
Fix from $1,600 2018-09-28
Kendo Ui MEDIUM 6.1
CVE-2018-14037

Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM …

No fix yet
Fix from $1,600 2018-09-28
Whatsup Gold CRITICAL 9.8
CVE-2018-8938

A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr…

Fix: 18.0+
Fix from $2,300 2018-05-01
Whatsup Gold CRITICAL 9.8
CVE-2018-8939

An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the…

Fix: 18.0+
Fix from $2,300 2018-05-01
Sitefinity HIGH 8.8
CVE-2017-18179

Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina…

No fix yet
Fix from $1,950 2018-02-12
Sitefinity MEDIUM 6.1
CVE-2017-18178

Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the tar…

No fix yet
Fix from $1,600 2018-02-12
Sitefinity MEDIUM 5.4
CVE-2017-18175

Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute o…

No fix yet
Fix from $1,600 2018-02-12
Sitefinity MEDIUM 5.4
CVE-2017-18176

Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is f…

No fix yet
Fix from $1,600 2018-02-12
Sitefinity MEDIUM 5.4
CVE-2017-18177

Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1.

No fix yet
Fix from $1,600 2018-02-12
Whatsup Gold CRITICAL 9.8
CVE-2018-5777

An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP s…

Fix: 17.1.1+
Fix from $2,300 2018-01-24
Whatsup Gold CRITICAL 9.8
CVE-2018-5778

An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP…

Fix: 17.1.1+
Fix from $2,300 2018-01-24
Sitefinity CRITICAL 9.8
CVE-2017-15883

Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic…

Mitigation only
Fix from $2,300 2018-01-08
Openedge CRITICAL 9.8
CVE-2015-9245

Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh…

Mitigation only
Fix from $2,300 2017-10-31
Telerik Ui For Asp.net Ajax CRITICAL 9.8
CVE-2017-11357 KEVEPSS 76%

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to per…

Fix: 2020.1.114+
Fix from $2,300 2017-08-23
Mixlib Archive HIGH 7.5
CVE-2017-1000026

Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary file…

Fix: after 0.3.0
Fix from $1,950 2017-07-17
Sitefinity CRITICAL 9.8
CVE-2017-9248 KEVEPSS 75%

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web…

Fix: 10.0.6412.0+
Fix from $2,300 2017-07-03
Telerik Reporting MEDIUM 6.1
CVE-2017-9140EPSS 10%

Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before …

Fix: 11.0.17.406+
Fix from $1,600 2017-05-22
Whatsup Gold HIGH 8.8
CVE-2016-1000000

Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection

Fix: after 16.4
Fix from $1,950 2016-10-06
Whatsup Gold CRITICAL 9.8
CVE-2015-8261

The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows re…

No fix yet
Fix from $2,300 2016-01-08
Whatsup Gold MEDIUM 6.9
CVE-2015-6005

Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTM…

Fix: after 16.3
Fix from $1,600 2015-12-27
Whatsup Gold MEDIUM 6.5
CVE-2015-6004

Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the Uniq…

Fix: after 16.3
Fix from $1,600 2015-12-27
Telerik Ui For Asp.net Ajax HIGH 7.5
CVE-2014-2217

Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remot…

Fix: after 2014.3.1209
Fix from $1,950 2014-12-25