Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: progress Clear
ID Title
CVE-2026-59690 Vulnerability in progress (CVE-2026-59690)
vulnerability in progress (CVE-2026-59690). Successful exploitation can lead to full system takeover.
CVE-2026-59688 OS Command Injection in progress (CVE-2026-59688)
OS command injection in progress (CVE-2026-59688). Successful exploitation can lead to full system takeover.
CVE-2026-59687 OS Command Injection in progress (CVE-2026-59687)
OS command injection in progress (CVE-2026-59687). Successful exploitation can lead to full system takeover.
CVE-2026-59689 Authorization Flaw in progress (CVE-2026-59689)
vulnerability in progress (CVE-2026-59689). Successful exploitation can lead to full system takeover.
CVE-2026-59686 OS Command Injection in progress (CVE-2026-59686)
OS command injection in progress (CVE-2026-59686). Successful exploitation can lead to full system takeover.
CVE-2026-15968 Cross-Site Scripting (XSS) in progress (CVE-2026-15968)
cross-site scripting in progress (CVE-2026-15968). Successful exploitation can lead to full system takeover.
CVE-2026-10697 Authentication Bypass in progress (CVE-2026-10697)
authentication bypass in progress (CVE-2026-10697). Successful exploitation can lead to full system takeover.
CVE-2026-15966 Vulnerability in progress (CVE-2026-15966)
vulnerability in progress (CVE-2026-15966). Successful exploitation can lead to full system takeover.
CVE-2026-15967 Vulnerability in progress (CVE-2026-15967)
vulnerability in progress (CVE-2026-15967). Successful exploitation can lead to full system takeover.
CVE-2026-14932 Vulnerability in progress (CVE-2026-14932)
vulnerability in progress (CVE-2026-14932). Risk of unauthorized operations or information disclosure.
CVE-2026-14865 Vulnerability in dos (CVE-2026-14865)
vulnerability in dos (CVE-2026-14865). Risk of unauthorized operations or information disclosure.
CVE-2026-13192 SSRF (Server-Side Request Forgery) in progress (CVE-2026-13192)
SSRF in progress (CVE-2026-13192). Confidential information can be exposed externally.
CVE-2026-13183 Vulnerability in progress (CVE-2026-13183)
vulnerability in progress (CVE-2026-13183). Confidential information can be exposed externally.
CVE-2026-13187 Vulnerability in progress (CVE-2026-13187)
vulnerability in progress (CVE-2026-13187). Successful exploitation can lead to full system takeover.
CVE-2026-13188 Vulnerability in progress (CVE-2026-13188)
vulnerability in progress (CVE-2026-13188). Data can be tampered with by attackers.
CVE-2026-13186 Path Traversal in path-traversal (CVE-2026-13186)
path traversal in path-traversal (CVE-2026-13186). Successful exploitation can lead to full system takeover.
CVE-2026-13184 Vulnerability in progress (CVE-2026-13184)
vulnerability in progress (CVE-2026-13184). Data can be tampered with by attackers.
CVE-2026-13185 Unsafe Deserialization in progress (CVE-2026-13185)
vulnerability in progress (CVE-2026-13185). Successful exploitation can lead to full system takeover.
CVE-2026-13190 Unsafe Deserialization in deserialization (CVE-2026-13190)
vulnerability in deserialization (CVE-2026-13190). Successful exploitation can lead to full system takeover.
CVE-2026-13189 Vulnerability in progress (CVE-2026-13189)
vulnerability in progress (CVE-2026-13189). Confidential information can be exposed externally.
CVE-2026-13182 Vulnerability in progress (CVE-2026-13182)
vulnerability in progress (CVE-2026-13182). Confidential information can be exposed externally.
CVE-2026-13181 Vulnerability in progress (CVE-2026-13181)
vulnerability in progress (CVE-2026-13181). Successful exploitation can lead to full system takeover.
CVE-2026-8801 Vulnerability in progress (CVE-2026-8801)
vulnerability in progress (CVE-2026-8801). Risk of unauthorized operations or information disclosure.
CVE-2026-8651 Vulnerability in progress (CVE-2026-8651)
vulnerability in progress (CVE-2026-8651). Risk of unauthorized operations or information disclosure.
CVE-2026-8650 Vulnerability in path-traversal (CVE-2026-8650)
vulnerability in path-traversal (CVE-2026-8650). Confidential information can be exposed externally.
CVE-2026-8800 Authorization Flaw in progress (CVE-2026-8800)
vulnerability in progress (CVE-2026-8800). Risk of unauthorized operations or information disclosure.
CVE-2026-8649 Vulnerability in progress (CVE-2026-8649)
vulnerability in progress (CVE-2026-8649). Successful exploitation can lead to full system takeover.
CVE-2026-10698 Vulnerability in progress (CVE-2026-10698)
vulnerability in progress (CVE-2026-10698). Successful exploitation can lead to full system takeover.
CVE-2026-10699 Vulnerability in progress (CVE-2026-10699)
vulnerability in progress (CVE-2026-10699). Risk of unauthorized operations or information disclosure.
CVE-2026-11903 Cross-Site Scripting (XSS) in progress (CVE-2026-11903)
cross-site scripting in progress (CVE-2026-11903). Successful exploitation can lead to full system takeover.
CVE-2026-8079 Authorization Flaw in progress (CVE-2026-8079)
vulnerability in progress (CVE-2026-8079). Confidential information can be exposed externally.
CVE-2026-9272 SQL Injection in progress (CVE-2026-9272)
SQL injection in progress (CVE-2026-9272). Confidential information can be exposed externally.
CVE-2026-8037 KEV [KEV] Command Injection in Progress connection-manager-for-objectscale (CVE-2026-8037)
command injection in Progress connection-manager-for-objectscale (CVE-2026-8037). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2026-7312 Vulnerability in progress (CVE-2026-7312)
vulnerability in progress (CVE-2026-7312). Confidential information can be exposed externally.
CVE-2026-7195 CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x,...
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x,...
CVE-2026-7198 Vulnerability in progress (CVE-2026-7198)
vulnerability in progress (CVE-2026-7198). Successful exploitation can lead to full system takeover.
CVE-2026-7313 CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from...
CVE-2026-7201 CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity...
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity...
CVE-2026-8488 Vulnerability in progress (CVE-2026-8488)
vulnerability in progress (CVE-2026-8488). Risk of unauthorized operations or information disclosure.
CVE-2026-8487 Vulnerability in progress (CVE-2026-8487)
vulnerability in progress (CVE-2026-8487). Confidential information can be exposed externally.
CVE-2026-8486 Vulnerability in progress (CVE-2026-8486)
vulnerability in progress (CVE-2026-8486). Risk of unauthorized operations or information disclosure.
CVE-2026-8485 Vulnerability in progress (CVE-2026-8485)
vulnerability in progress (CVE-2026-8485). Risk of unauthorized operations or information disclosure.
CVE-2026-3692 OS Command Injection in progress (CVE-2026-3692)
OS command injection in progress (CVE-2026-3692). Successful exploitation can lead to full system takeover.
CVE-2026-2737 Cross-Site Scripting (XSS) in progress (CVE-2026-2737)
cross-site scripting in progress (CVE-2026-2737). Risk of unauthorized operations or information disclosure.
CVE-2025-13444 OS Command Injection in progress (CVE-2025-13444)
OS command injection in progress (CVE-2025-13444). Successful exploitation can lead to full system takeover.
CVE-2024-4885 KEV [KEV] Path Traversal in Progress whatsup-gold (CVE-2024-4885)
path traversal in Progress whatsup-gold (CVE-2024-4885). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-12251 Command Injection in telerik (CVE-2024-12251)
command injection in telerik (CVE-2024-12251). Successful exploitation can lead to full system takeover.
CVE-2024-1212 KEV [KEV] OS Command Injection in Progress kemp-loadmaster (CVE-2024-1212)
OS command injection in Progress kemp-loadmaster (CVE-2024-1212). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2024-6670 KEV [KEV] SQL Injection in Progress whatsup-gold (CVE-2024-6670)
SQL injection in Progress whatsup-gold (CVE-2024-6670). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2024-4358 KEV [KEV] Vulnerability in Progress telerik-report-server (CVE-2024-4358)
vulnerability in Progress telerik-report-server (CVE-2024-4358). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →