Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-59690 |
|
Vulnerability in progress (CVE-2026-59690)
vulnerability in progress (CVE-2026-59690). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59688 |
|
OS Command Injection in progress (CVE-2026-59688)
OS command injection in progress (CVE-2026-59688). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59687 |
|
OS Command Injection in progress (CVE-2026-59687)
OS command injection in progress (CVE-2026-59687). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59689 |
|
Authorization Flaw in progress (CVE-2026-59689)
vulnerability in progress (CVE-2026-59689). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59686 |
|
OS Command Injection in progress (CVE-2026-59686)
OS command injection in progress (CVE-2026-59686). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15968 |
|
Cross-Site Scripting (XSS) in progress (CVE-2026-15968)
cross-site scripting in progress (CVE-2026-15968). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10697 |
|
Authentication Bypass in progress (CVE-2026-10697)
authentication bypass in progress (CVE-2026-10697). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15966 |
|
Vulnerability in progress (CVE-2026-15966)
vulnerability in progress (CVE-2026-15966). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15967 |
|
Vulnerability in progress (CVE-2026-15967)
vulnerability in progress (CVE-2026-15967). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14932 |
|
Vulnerability in progress (CVE-2026-14932)
vulnerability in progress (CVE-2026-14932). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14865 |
|
Vulnerability in dos (CVE-2026-14865)
vulnerability in dos (CVE-2026-14865). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13192 |
|
SSRF (Server-Side Request Forgery) in progress (CVE-2026-13192)
SSRF in progress (CVE-2026-13192). Confidential information can be exposed externally.
|
| CVE-2026-13183 |
|
Vulnerability in progress (CVE-2026-13183)
vulnerability in progress (CVE-2026-13183). Confidential information can be exposed externally.
|
| CVE-2026-13187 |
|
Vulnerability in progress (CVE-2026-13187)
vulnerability in progress (CVE-2026-13187). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13188 |
|
Vulnerability in progress (CVE-2026-13188)
vulnerability in progress (CVE-2026-13188). Data can be tampered with by attackers.
|
| CVE-2026-13186 |
|
Path Traversal in path-traversal (CVE-2026-13186)
path traversal in path-traversal (CVE-2026-13186). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13184 |
|
Vulnerability in progress (CVE-2026-13184)
vulnerability in progress (CVE-2026-13184). Data can be tampered with by attackers.
|
| CVE-2026-13185 |
|
Unsafe Deserialization in progress (CVE-2026-13185)
vulnerability in progress (CVE-2026-13185). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13190 |
|
Unsafe Deserialization in deserialization (CVE-2026-13190)
vulnerability in deserialization (CVE-2026-13190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13189 |
|
Vulnerability in progress (CVE-2026-13189)
vulnerability in progress (CVE-2026-13189). Confidential information can be exposed externally.
|
| CVE-2026-13182 |
|
Vulnerability in progress (CVE-2026-13182)
vulnerability in progress (CVE-2026-13182). Confidential information can be exposed externally.
|
| CVE-2026-13181 |
|
Vulnerability in progress (CVE-2026-13181)
vulnerability in progress (CVE-2026-13181). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8801 |
|
Vulnerability in progress (CVE-2026-8801)
vulnerability in progress (CVE-2026-8801). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8651 |
|
Vulnerability in progress (CVE-2026-8651)
vulnerability in progress (CVE-2026-8651). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8650 |
|
Vulnerability in path-traversal (CVE-2026-8650)
vulnerability in path-traversal (CVE-2026-8650). Confidential information can be exposed externally.
|
| CVE-2026-8800 |
|
Authorization Flaw in progress (CVE-2026-8800)
vulnerability in progress (CVE-2026-8800). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8649 |
|
Vulnerability in progress (CVE-2026-8649)
vulnerability in progress (CVE-2026-8649). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10698 |
|
Vulnerability in progress (CVE-2026-10698)
vulnerability in progress (CVE-2026-10698). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10699 |
|
Vulnerability in progress (CVE-2026-10699)
vulnerability in progress (CVE-2026-10699). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11903 |
|
Cross-Site Scripting (XSS) in progress (CVE-2026-11903)
cross-site scripting in progress (CVE-2026-11903). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8079 |
|
Authorization Flaw in progress (CVE-2026-8079)
vulnerability in progress (CVE-2026-8079). Confidential information can be exposed externally.
|
| CVE-2026-9272 |
|
SQL Injection in progress (CVE-2026-9272)
SQL injection in progress (CVE-2026-9272). Confidential information can be exposed externally.
|
| CVE-2026-8037 KEV |
|
[KEV] Command Injection in Progress connection-manager-for-objectscale (CVE-2026-8037)
command injection in Progress connection-manager-for-objectscale (CVE-2026-8037). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-7312 |
|
Vulnerability in progress (CVE-2026-7312)
vulnerability in progress (CVE-2026-7312). Confidential information can be exposed externally.
|
| CVE-2026-7195 |
|
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x,...
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x,...
|
| CVE-2026-7198 |
|
Vulnerability in progress (CVE-2026-7198)
vulnerability in progress (CVE-2026-7198). Successful exploitation can lead to full system takeover.
|
| CVE-2026-7313 |
|
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
|
| CVE-2026-7201 |
|
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity...
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity...
|
| CVE-2026-8488 |
|
Vulnerability in progress (CVE-2026-8488)
vulnerability in progress (CVE-2026-8488). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8487 |
|
Vulnerability in progress (CVE-2026-8487)
vulnerability in progress (CVE-2026-8487). Confidential information can be exposed externally.
|
| CVE-2026-8486 |
|
Vulnerability in progress (CVE-2026-8486)
vulnerability in progress (CVE-2026-8486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8485 |
|
Vulnerability in progress (CVE-2026-8485)
vulnerability in progress (CVE-2026-8485). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3692 |
|
OS Command Injection in progress (CVE-2026-3692)
OS command injection in progress (CVE-2026-3692). Successful exploitation can lead to full system takeover.
|
| CVE-2026-2737 |
|
Cross-Site Scripting (XSS) in progress (CVE-2026-2737)
cross-site scripting in progress (CVE-2026-2737). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-13444 |
|
OS Command Injection in progress (CVE-2025-13444)
OS command injection in progress (CVE-2025-13444). Successful exploitation can lead to full system takeover.
|
| CVE-2024-4885 KEV |
|
[KEV] Path Traversal in Progress whatsup-gold (CVE-2024-4885)
path traversal in Progress whatsup-gold (CVE-2024-4885). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-12251 |
|
Command Injection in telerik (CVE-2024-12251)
command injection in telerik (CVE-2024-12251). Successful exploitation can lead to full system takeover.
|
| CVE-2024-1212 KEV |
|
[KEV] OS Command Injection in Progress kemp-loadmaster (CVE-2024-1212)
OS command injection in Progress kemp-loadmaster (CVE-2024-1212). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2024-6670 KEV |
|
[KEV] SQL Injection in Progress whatsup-gold (CVE-2024-6670)
SQL injection in Progress whatsup-gold (CVE-2024-6670). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-4358 KEV |
|
[KEV] Vulnerability in Progress telerik-report-server (CVE-2024-4358)
vulnerability in Progress telerik-report-server (CVE-2024-4358). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|