← Back to News Iceland Security Dashboard Browse all tags
progress

Progress

sitefinity 10telerik-ui-for-ajax 8telerik-ui-for-asp-net-ajax 4moveit-transfer 3whatsup-gold 2whatsup gold 2adc-products 2adc-loadmaster 2ws_ftp server 1ws-ftp-server 1telerik-report-server 1telerik ui for asp.net ajax 1telerik report server 1moveit transfer 1kemp-loadmaster 1kemp loadmaster 1asp.net ajax and sitefinity 1

CVEs tagged with this vendor (29)

CVE-2017-11317 🚨 User Interface (UI) for ASP.NET AJAX
CVE-2017-11317 is a critical vulnerability in Progress Telerik UI for ASP.NET AJAX versions prior to R1 2017 and R2 before R2 2017 SP2, caused by weak encryptio…
CVE-2017-11357 🚨 User Interface (UI) for ASP.NET AJAX
CVE-2017-11357 is a critical remote code execution vulnerability in Progress Telerik UI for ASP.NET AJAX prior to R2 2017 SP2, caused by improper input restrict…
CVE-2017-9248 🚨 ASP.NET AJAX and Sitefinity
CVE-2017-9248 is a critical vulnerability in Progress Telerik UI for ASP.NET AJAX and Sitefinity affecting versions prior to R2 2017 SP1 and 10.0.6412.0 respect…
CVE-2019-18935 🚨 Telerik UI for ASP.NET AJAX
CVE-2019-18935 is a critical deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023 that allows remote code execution…
CVE-2023-34362 🚨 MOVEit Transfer
CVE-2023-34362 is a critical SQL injection vulnerability (CWE-89) in Progress MOVEit Transfer affecting versions prior to 2021.0.6, 2021.1.4, 2022.0.4, 2022.1.5…
CVE-2023-40044 🚨 WS_FTP Server
CVE-2023-40044 is a critical remote code execution vulnerability in WS_FTP Server versions prior to 8.7.4 and 8.8.2, caused by insecure .NET deserialization in …
CVE-2024-1212 🚨 Kemp LoadMaster
CVE-2024-1212 is a critical command injection vulnerability (CWE-78) in Progress Kemp LoadMaster that allows unauthenticated remote attackers to execute arbitra…
CVE-2024-4358 🚨 Telerik Report Server
CVE-2024-4358 is a critical authentication bypass vulnerability in Progress Telerik Report Server versions 2024 Q1 (10.0.24.305) and earlier running on IIS. It …
CVE-2024-4885 🚨 WhatsUp Gold
CVE-2024-4885 is a critical Remote Code Execution vulnerability in Progress WhatsUp Gold versions prior to 2023.1.3, allowing unauthenticated attackers to execu…
CVE-2024-6670 🚨 WhatsUp Gold
CVE-2024-6670 is a critical SQL Injection vulnerability (CWE-89) in Progress WhatsUp Gold versions prior to 2024.0.0, allowing unauthenticated attackers to retr…
CVE-2026-7312 CVSS 10.0 sitefinity
CVE-2026-7312 is a critical vulnerability in Progress Sitefinity versions 14.0.7700 through 14.4.8152, and 15.0.8200 through 15.4.8630, classified under CWE-522…
CVE-2026-7198 CVSS 9.8 sitefinity
CVE-2026-7198 is a critical vulnerability in Progress Sitefinity versions 15.4.8623 through 15.4.8629 caused by improper access control. It allows remote unauth…
CVE-2026-7195 CVSS 8.8 sitefinity
CVE-2026-7195 is a high-severity improper input validation vulnerability (CWE-20) affecting Progress Sitefinity versions 14.1.x through 14.3.x, 14.4.x before 14…
CVE-2026-7201 CVSS 8.8 sitefinity
CVE-2026-7201 is a high-severity authorization bypass vulnerability (CWE-639) affecting Progress Sitefinity versions 15.2.x prior to 15.2.8441, 15.3.x prior to …
CVE-2026-7313 CVSS 8.7 sitefinity
CVE-2026-7313 is a high-severity information disclosure vulnerability in Progress Sitefinity versions 8.0.5700 through 13.3.7652, classified under CWE-522 for i…
CVE-2026-3517 CVSS 8.4
CVE-2026-3517 is a high-severity OS command injection vulnerability (CWE-77) affecting Progress ADC Products, specifically the LoadMaster appliance. It allows a…
CVE-2026-3518 CVSS 8.4
CVE-2026-3518 is a HIGH severity OS Command Injection vulnerability (CWE-77) in the API of Progress ADC Products, specifically affecting the 'killsession' comma…
CVE-2026-3519 CVSS 8.4
CVE-2026-3519 is a high-severity OS command injection vulnerability (CWE-77) affecting Progress ADC Products, specifically the LoadMaster appliance. It allows a…
CVE-2026-13181 CVSS 8.1
CVE-2026-13181 is a high-severity remote code execution vulnerability in Progress Telerik UI for AJAX prior to version 2026.2.708. The flaw allows attackers to …
CVE-2026-13185 CVSS 8.1
CVE-2026-13185 is a high-severity deserialization vulnerability (CWE-502) affecting Progress Telerik UI for AJAX versions prior to v2026.2.708. The flaw allows …
CVE-2026-13186 CVSS 8.1
CVE-2026-13186 is a high-severity path traversal vulnerability (CWE-22) in Progress Telerik UI for AJAX prior to version 2026.2.708. The flaw allows attacker-co…
CVE-2026-13187 CVSS 8.1
CVE-2026-13187 is a HIGH severity vulnerability (CVSS 8.1) affecting Progress Telerik UI for AJAX versions prior to v2026.2.708. The flaw involves CWE-470, allo…
CVE-2026-13190 CVSS 8.1
CVE-2026-13190 is a high-severity deserialization vulnerability in Progress Telerik UI for AJAX versions prior to 2026.2.708. It allows unsafe type instantiatio…
CVE-2026-13182 CVSS 7.5
CVE-2026-13182 is a high severity vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708 affecting the RadAsyncUpload component. The flaw allows rem…
CVE-2026-13183 CVSS 7.5
CVE-2026-13183 is a timing side-channel vulnerability in Progress Telerik UI for AJAX prior to v2026.2.708 affecting the RadAsyncUpload component. The flaw allo…
CVE-2026-13189 CVSS 7.5
CVE-2026-13189 affects Progress Telerik UI for AJAX versions prior to v2026.2.708 due to insufficient validation of the language parameter in the spell check ha…
CVE-2026-10698
CVE-2026-10698 is a HIGH severity vulnerability (CVSS 7.2) in Progress MOVEit Transfer affecting Custom Reports modules. It is classified as CWE-943, representi…
CVE-2026-10699
CVE-2026-10699 is a HIGH severity memory corruption vulnerability (CWE-401) affecting Progress MOVEit Transfer Custom Reports modules. It impacts versions from …
CVE-2026-8037
CVE-2026-8037 is a critical OS command injection vulnerability (CWE-77) affecting Progress ADC Products, specifically the LoadMaster appliance. It allows unauth…

Articles tagged with Progress (3)