Vulnerability index

Browse CVEs

259 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2017-18639 Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title, /Content/List Parameter : Lis… Sitefinity Cms 10.1+ Fix from $1,6002019-11-06 MEDIUM 5.3 CVE-2019-12143 A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string … Ws Ftp Server 8.6.1+ Fix from $1,6002019-06-11 MEDIUM 6.5 CVE-2019-7215 Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remai… Sitefinity 7.0.5143 / 7.1.5243+ Fix from $1,6002019-06-06 HIGH 7.8 CVE-2019-12097 Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privile… Fiddler Mitigation only Fix from $1,9502019-06-03 MEDIUM 5.3 CVE-2018-17060 Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's … Telerik Extensions For Asp.net Mvc Mitigation only Fix from $1,6002018-10-08 MEDIUM 6.1 CVE-2018-17053 Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject a… Sitefinity Cms after 11.0 Fix from $1,6002018-10-03 MEDIUM 6.1 CVE-2018-17054 Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject a… Sitefinity Cms after 11.0 Fix from $1,6002018-10-03 HIGH 7.5 CVE-2018-17055 An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. Sitefinity after 11.0 Fix from $1,9502018-09-28 MEDIUM 6.1 CVE-2018-17056 Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbi… Sitefinity Cms after 11.0 Fix from $1,6002018-09-28 MEDIUM 6.1 CVE-2018-14037 Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM … Kendo Ui No fix yet Fix from $1,6002018-09-28 CRITICAL 9.8 CVE-2018-8938 A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially cr… Whatsup Gold 18.0+ Fix from $2,3002018-05-01 CRITICAL 9.8 CVE-2018-8939 An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the… Whatsup Gold 18.0+ Fix from $2,3002018-05-01 HIGH 8.8 CVE-2017-18179 Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina… Sitefinity No fix yet Fix from $1,9502018-02-12 MEDIUM 6.1 CVE-2017-18178 Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the tar… Sitefinity No fix yet Fix from $1,6002018-02-12 MEDIUM 5.4 CVE-2017-18175 Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demonstrated by the src attribute o… Sitefinity No fix yet Fix from $1,6002018-02-12 MEDIUM 5.4 CVE-2017-18176 Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the application's own code. This is f… Sitefinity No fix yet Fix from $1,6002018-02-12 MEDIUM 5.4 CVE-2017-18177 Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is fixed in 10.1. Sitefinity No fix yet Fix from $1,6002018-02-12 CRITICAL 9.8 CVE-2018-5777 An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP s… Whatsup Gold 17.1.1+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2018-5778 An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP… Whatsup Gold 17.1.1+ Fix from $2,3002018-01-24 CRITICAL 9.8 CVE-2017-15883 Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic… Sitefinity Mitigation only Fix from $2,3002018-01-08 CRITICAL 9.8 CVE-2015-9245 Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from wh… Openedge Mitigation only Fix from $2,3002017-10-31 CRITICAL 9.8 CVE-2017-11357 KEVEPSS 76% Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to per… Telerik Ui For Asp.net Ajax 2020.1.114+ Fix from $2,3002017-08-23 HIGH 7.5 CVE-2017-1000026 Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary file… Mixlib Archive after 0.3.0 Fix from $1,9502017-07-17 CRITICAL 9.8 CVE-2017-9248 KEVEPSS 75% Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web… Sitefinity 10.0.6412.0+ Fix from $2,3002017-07-03 MEDIUM 6.1 CVE-2017-9140EPSS 10% Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before … Telerik Reporting 11.0.17.406+ Fix from $1,6002017-05-22 HIGH 8.8 CVE-2016-1000000 Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection Whatsup Gold after 16.4 Fix from $1,9502016-10-06 CRITICAL 9.8 CVE-2015-8261 The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows re… Whatsup Gold No fix yet Fix from $2,3002016-01-08 MEDIUM 6.9 CVE-2015-6005 Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTM… Whatsup Gold after 16.3 Fix from $1,6002015-12-27 MEDIUM 6.5 CVE-2015-6004 Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the Uniq… Whatsup Gold after 16.3 Fix from $1,6002015-12-27 HIGH 7.5 CVE-2014-2217 Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remot… Telerik Ui For Asp.net Ajax after 2014.3.1209 Fix from $1,9502014-12-25