progress
55 known vulnerabilities affecting progress products.
Products
telerik_ui_for_asp.net_ajax 14
marklogic_server 10
connection_manager_for_objectscale 7
ecs_connection_manager 7
moveit_web_application_firewall 7
loadmaster 7
whatsup_gold 5
sitefinity 5
sharefile_storage_zones_controller 4
moveit_automation 4
moveit_transfer 4
flowmon_anomaly_detection_system 2
multi-tenant_hypervisor 1
multi-tenant_loadmaster 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-8037 | Act now | 99.6% | 9.6 | ● | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC … |
| CVE-2017-11357 | Act now | 77.7% | 9.8 | ● | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restri… |
| CVE-2025-13444 | Medium | 27.2% | 8.4 | OS Command Injection Remote Code Execution Vulnerability in API in Progress Load… | |
| CVE-2026-59686 | Medium | 1.4% | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Conne… | |
| CVE-2026-59687 | Medium | 0.7% | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Conne… | |
| CVE-2026-59688 | Medium | 0.7% | 8.4 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Conne… | |
| CVE-2026-13190 | Medium | 0.7% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulner… | |
| CVE-2026-16139 | Medium | 0.7% | 7.2 | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, … | |
| CVE-2026-13189 | Medium | 0.5% | 7.5 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation … | |
| CVE-2026-13186 | Medium | 0.5% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnera… | |
| CVE-2026-15724 | Medium | 0.5% | 8.7 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.… | |
| CVE-2026-9192 | Medium | 0.5% | 9.8 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLo… | |
| CVE-2026-16137 | Medium | 0.5% | 7.2 | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with v… | |
| CVE-2026-13181 | Medium | 0.5% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata c… | |
| CVE-2026-13185 | Medium | 0.5% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cooki… | |
| CVE-2026-7195 | Medium | 0.5% | 8.8 | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x … | |
| CVE-2026-13187 | Medium | 0.5% | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider t… | |
| CVE-2026-7198 | Medium | 0.4% | 9.8 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.862… | |
| CVE-2026-9195 | Medium | 0.4% | 9.3 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic … | |
| CVE-2026-7312 | Medium | 0.4% | 10.0 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefi… | |
| CVE-2026-65941 | Medium | 0.4% | 8.8 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote att… | |
| CVE-2026-9190 | Medium | 0.4% | 9.1 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkL… | |
| CVE-2026-7329 | Medium | 0.4% | 9.9 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic RES… | |
| CVE-2026-7201 | Medium | 0.3% | 8.8 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Pro… | |
| CVE-2026-13182 | Medium | 0.3% | 7.5 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-st… | |
| CVE-2026-13183 | Medium | 0.3% | 7.5 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload me… | |
| CVE-2026-7313 | Medium | 0.3% | 8.7 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefi… | |
| CVE-2026-7557 | Medium | 0.3% | 9.1 | An improper verification of cryptographic signature vulnerability in the SAML au… | |
| CVE-2026-8709 | Medium | 0.3% | 9.9 | An improper privilege management vulnerability in the REST API document patch op… | |
| CVE-2026-9193 | Medium | 0.3% | 9.9 | An improper privilege management vulnerability in the Hadoop integration of Prog… | |
| CVE-2026-10697 | Medium | 0.3% | 7.5 | Improper Authentication vulnerability in Progress MOVEit Transfer. This issue a… | |
| CVE-2026-16138 | Medium | 0.3% | 8.0 | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsaf… | |
| CVE-2026-65937 | Medium | 0.2% | 8.0 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can… | |
| CVE-2026-7327 | Medium | 0.2% | 8.1 | An improper privilege management vulnerability in the REST API document processi… | |
| CVE-2026-59690 | Medium | 0.2% | 8.0 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Conne… | |
| CVE-2026-9203 | Medium | 0.2% | 8.5 | A server-side request forgery vulnerability in Progress MarkLogic Server before … | |
| CVE-2026-13184 | Medium | 0.2% | 7.5 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.Conf… | |
| CVE-2026-15966 | Medium | 0.2% | 7.5 | Permissive cross-domain security policy with untrusted domains vulnerability in … | |
| CVE-2026-15967 | Medium | 0.2% | 7.5 | Insufficient session expiration vulnerability in Progress MOVEit Transfer. This… | |
| CVE-2026-59689 | Medium | 0.2% | 8.0 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Co… | |
| CVE-2026-15968 | Medium | 0.2% | 7.1 | Improper neutralization of input during web page generation ('cross-site scripti… | |
| CVE-2026-7326 | Medium | 0.1% | 7.5 | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic… | |
| CVE-2026-14865 | Low | 0.4% | 5.3 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuild… | |
| CVE-2026-8486 | Low | 0.4% | 5.3 | Allocation of resources without limits or throttling vulnerability in Progress S… | |
| CVE-2026-8488 | Low | 0.4% | 4.3 | Allocation of resources without limits or throttling vulnerability in Progress S… | |
| CVE-2026-14932 | Low | 0.4% | 6.5 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart co… | |
| CVE-2026-8485 | Low | 0.3% | 5.9 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automat… | |
| CVE-2026-8487 | Low | 0.3% | 6.5 | Incorrect default permissions vulnerability in Progress Software MOVEit Automati… | |
| CVE-2026-65939 | Low | 0.3% | 6.8 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can cre… | |
| CVE-2026-13192 | Low | 0.2% | 6.5 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation … |
Page 1 of 2
Next →