Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-9272 In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged use… Flowmon Anomaly Detection System 12.5.6 / 13.0.5+ Fix from $1,9502026-07-02 HIGH 7.3 CVE-2026-8079 In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request dur… Flowmon 12.5.9 / 13.0.11+ Fix from $1,9502026-07-02 CRITICAL 9.8 CVE-2026-8037 KEVEPSS 99% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary com… Connection Manager For Objectscale 7.2.54.18 / 7.2.63.2+ Fix from $2,3002026-06-04 CRITICAL 9.8 CVE-2026-7198 CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access… Sitefinity 15.4.8630+ Fix from $2,3002026-06-02 HIGH 8.8 CVE-2026-7201 CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, an… Sitefinity 15.2.8441 / 15.3.8531+ Fix from $1,9502026-06-02 HIGH 8.1 CVE-2026-7195 CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.… Sitefinity 14.4.8152 / 15.0.8234+ Fix from $1,9502026-06-02 HIGH 7.5 CVE-2026-7312 CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234,… Sitefinity 14.4.8152 / 15.0.8234+ Fix from $1,9502026-06-02 HIGH 7.5 CVE-2026-8486 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-8487 Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEi… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-8488 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue af… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 HIGH 7.5 CVE-2026-8485 Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automatio… Moveit Automation 2025.0.11 / 2025.1.7+ Fix from $1,9502026-05-20 CRITICAL 9.8 CVE-2026-4670EPSS 6% Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVE… Moveit Automation 2024.1.8 / 2025.1.5+ Fix from $2,3002026-04-30 HIGH 8.8 CVE-2026-5174 Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: fr… Moveit Automation 2024.1.8 / 2025.1.5+ Fix from $1,9502026-04-30 CRITICAL 9.8 CVE-2026-6023 In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto… Telerik Ui For Asp.net Ajax 2026.1.421+ Fix from $2,3002026-04-22 HIGH 7.5 CVE-2026-6022 In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file up… Telerik Ui For Asp.net Ajax 2026.1.421+ Fix from $1,9502026-04-22 HIGH 7.2 CVE-2026-4048 OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to ex… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-3517EPSS 18% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” p… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-3518EPSS 20% OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to e… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 7.2 CVE-2026-3519 OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” pe… Connection Manager For Objectscale 7.2.54.17 / 7.2.63.1+ Fix from $1,9502026-04-20 HIGH 8.8 CVE-2026-3692 In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the repo… Flowmon 12.5.8+ Fix from $1,9502026-04-02 MEDIUM 6.1 CVE-2026-2737 A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an a… Flowmon 12.5.8 / 13.0.6+ Fix from $1,6002026-04-02 CRITICAL 9.8 CVE-2026-2699EPSS 58% Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to … Sharefile Storage Zones Controller 5.12.4+ Fix from $2,3002026-04-02 HIGH 8.8 CVE-2026-2701EPSS 57% Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. Sharefile Storage Zones Controller 5.12.4+ Fix from $1,9502026-04-02 MEDIUM 5.9 CVE-2026-2878 In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable … Telerik Ui For Asp.net Ajax 2026.1.225+ Fix from $1,6002026-02-25 MEDIUM 6.8 CVE-2025-13447EPSS 26% OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe… Connection Manager For Objectscale* 7.1.35.15 / 7.2.54.16+ Fix from $1,6002026-01-13 MEDIUM 6.8 CVE-2025-13444EPSS 26% OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” pe… Connection Manager For Objectscale 7.1.35.15 / 7.2.54.16+ Fix from $1,6002026-01-13 HIGH 8.8 CVE-2025-13774 A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to… Flowmon Anomaly Detection System after 13.0.1 Fix from $1,9502026-01-13 HIGH 7.5 CVE-2025-11235 Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 … Moveit Transfer 2022.0.10 / 2022.1.11+ Fix from $1,9502026-01-07 MEDIUM 5.3 CVE-2025-13147 Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 befor… Moveit Transfer 2024.1.8 / 2025.0.4+ Fix from $1,6002025-11-19 HIGH 8.4 CVE-2025-6504 In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a … Hybrid Data Pipeline 4.6.2.2978+ Fix from $1,9502025-07-29