Progress
160 known vulnerabilities
Top Products
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may cr
A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a ma
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted config
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyn
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MO
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with exte
Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is
Progress Sitefinity CMS before 10.1 allows XSS via /Pages Parameter : Page Title, /Content/News Parameter : News Title,
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An
Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie
Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to co
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to acce
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows
Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows re
An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbit
An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit speci
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious act
Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a passwor
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the r
Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is f
Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the appl
Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demons
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities a
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a m
Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and conseque
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to s
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attacker
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms
Frequently Asked Questions
How many CVEs affect Progress?
Progress has 160 CVE records in our database, including 20 critical and 74 high severity vulnerabilities. 3 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Progress vulnerabilities?
Progress has 20 critical severity (CVSS 9.0+) and 74 high severity (CVSS 7.0-8.9) vulnerabilities. 3 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Progress vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Progress products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Progress Vulnerabilities
CyberStrike scans your infrastructure for Progress vulnerabilities and provides real-time remediation guidance.
Get Started