Filtered by vendor Progress
Subscribe
Total
258 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2014-5287 | 1 Progress | 1 Loadmaster | 2026-07-13 | 6.8 MEDIUM | 8.8 HIGH |
| A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI). | |||||
| CVE-2024-1212 | 1 Progress | 1 Loadmaster | 2026-07-13 | N/A | 10.0 CRITICAL |
| Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | |||||
| CVE-2026-8037 | 1 Progress | 3 Connection Manager For Objectscale, Ecs Connection Manager, Loadmaster | 2026-07-13 | N/A | 9.6 CRITICAL |
| OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |||||
| CVE-2026-8649 | 1 Progress | 1 Moveit Transfer | 2026-07-10 | N/A | 6.4 MEDIUM |
| Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-10698 | 1 Progress | 1 Moveit Transfer | 2026-07-10 | N/A | 7.2 HIGH |
| Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |||||
| CVE-2026-10699 | 1 Progress | 1 Moveit Transfer | 2026-07-10 | N/A | 7.5 HIGH |
| Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |||||
| CVE-2026-11903 | 1 Progress | 1 Moveit Transfer | 2026-07-10 | N/A | 8.0 HIGH |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. | |||||
| CVE-2026-8650 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 4.5 MEDIUM |
| Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-8651 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 3.7 LOW |
| Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-8800 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 2.7 LOW |
| Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |||||
| CVE-2026-8801 | 1 Progress | 1 Moveit Transfer | 2026-07-09 | N/A | 3.5 LOW |
| Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. | |||||
| CVE-2026-9272 | 1 Progress | 1 Flowmon Anomaly Detection System | 2026-07-07 | N/A | 8.1 HIGH |
| In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification. | |||||
| CVE-2026-8079 | 1 Progress | 1 Flowmon | 2026-07-06 | N/A | 7.3 HIGH |
| In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration. | |||||
| CVE-2026-3692 | 1 Progress | 1 Flowmon | 2026-07-06 | N/A | 8.8 HIGH |
| In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server. | |||||
| CVE-2026-2737 | 1 Progress | 1 Flowmon | 2026-07-06 | N/A | 6.1 MEDIUM |
| A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |||||
| CVE-2026-8488 | 1 Progress | 1 Moveit Automation | 2026-06-17 | N/A | 4.3 MEDIUM |
| Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |||||
| CVE-2026-8487 | 1 Progress | 1 Moveit Automation | 2026-06-17 | N/A | 6.5 MEDIUM |
| Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |||||
| CVE-2026-8486 | 1 Progress | 1 Moveit Automation | 2026-06-17 | N/A | 5.3 MEDIUM |
| Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |||||
| CVE-2026-8485 | 1 Progress | 1 Moveit Automation | 2026-06-17 | N/A | 5.9 MEDIUM |
| Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |||||
| CVE-2026-7313 | 1 Progress | 1 Sitefinity | 2026-06-17 | N/A | 8.7 HIGH |
| CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight, non-default site configuration and valid back-end authorization. | |||||
