Vulnerabilidades en Progress

38 resultados
Análisis Vexday

A Progress acumula 34 vulnerabilidades na base, com 9 publicadas nos últimos 90 dias, indicando pressão contínua de segurança. Nenhuma está sob ataque ativo (KEV) atualmente, mas 6 críticas estão documentadas, com validação de entrada (CWE-20) como fraqueza recorrente. O volume recente de divulgações requer atenção ao ciclo de patching, mas o risco imediato de exploração em massa não está evidente.

CVE-2024-5806CRITICALMOVEit Transfer Authentication Bypass VulnerabilityEPSS 81.5%CVE-2026-2699CRITICALEAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)EPSS 58.4%CVE-2026-2701CRITICALRCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)EPSS 56.7%CVE-2024-7591CRITICALImproper Input Validation vulnerability in Progress LoadMaster allows OS Command InjectionEPSS 43.8%CVE-2024-5805CRITICALMOVEit Gateway Authentication Bypass VulnerabilityEPSS 7.6%CVE-2024-56132HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 6.3%CVE-2024-56131HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 6.1%CVE-2025-1758MEDIUMImproper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and aboveEPSS 4.8%CVE-2024-1403CRITICALAuthentication Bypass in OpenEdge Authentication Gateway and AdminServerEPSS 3.3%CVE-2024-8755HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 1.2%CVE-2024-6576HIGHMOVEit Transfer Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-56135HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2024-56134HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2024-56133HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2024-7345HIGHDirect local client connections to MS Agents can bypass authenticationEPSS 0.6%CVE-2024-6658HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.EPSS 0.6%CVE-2026-10698HIGHTable scope bypass vulnerability in custom reportsEPSS 0.5%CVE-2025-10932HIGHAS2 module allows uncontrolled file uploadsEPSS 0.5%CVE-2026-8650MEDIUMAuthenticated Path Traversal allows MOVEit admins to view arbitrary system filesEPSS 0.4%CVE-2026-8801LOWFile Extension Restriction Bypass in MOVEit TransferEPSS 0.3%