Vulnerabilidades en Progress Software Corporation

101 resultados
Análisis Vexday

Com 4,65% das CVEs catalogadas confirmadas no CISA KEV, a Progress Software Corporation apresenta uma taxa de exploração ativa 10,3 vezes acima da média geral do catálogo, sinalizando que vulnerabilidades nesse ecossistema atraem atenção consistente de agentes maliciosos. Das 86 CVEs registradas, 19 são de severidade crítica e 5 contam com prova de conceito pública, o que amplia a superfície de risco para organizações que não mantêm ciclos ágeis de atualização. O pior caso ativo hoje é o CVE-2024-4885, com EPSS de 0,9929 — valor extremamente elevado que indica altíssima probabilidade de exploração —, exigindo atenção prioritária de equipes de resposta. O tipo de falha mais recorrente (CWE-79) aponta para problemas persistentes de sanitização de saída, aspecto que deve ser considerado em revisões de configuração e controles de segurança em camada de aplicação.

CVE-2026-65940MEDIUMWhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.EPSS 0.4%CVE-2023-40048MEDIUMWS_FTP Server Cross-Site Request Forgery (CSRF) VulnerabilityEPSS 0.4%CVE-2024-7294HIGHUncontrolled resource consumption of anonymous endpointsEPSS 0.3%CVE-2026-9203HIGHServer-side request forgery in Progress MarkLogic ServerEPSS 0.3%CVE-2024-7293HIGHPassword policy for new users is not strong enoughEPSS 0.3%CVE-2024-7292HIGHAccount Controller allows high count of login attemptsEPSS 0.3%CVE-2025-7389HIGHUnauthorized Arbitrary File Read via RMI in AdminServer InterfaceEPSS 0.3%CVE-2025-1968HIGHInsufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allEPSS 0.3%CVE-2024-11625HIGHInformation Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from EPSS 0.3%CVE-2024-4200HIGHProgress Telerik Reporting Local Deserialization VulnerabilityEPSS 0.3%CVE-2023-42658HIGHInSpec Archive Command Vulnerable to Maliciously Crafted ProfileEPSS 0.3%CVE-2024-9825MEDIUMThe Chef Habitat builder is impacted by Indirect Object reference(IDOR) by deletion of personal access tokenEPSS 0.3%CVE-2024-3543MEDIUMLoadMaster Reversible Password Encryption AlgorithmEPSS 0.3%CVE-2024-4202HIGHProgress Telerik Reporting Local Instantiation VulnerabilityEPSS 0.3%CVE-2025-2572MEDIUMWhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityEPSS 0.3%CVE-2026-65938MEDIUMWhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.EPSS 0.3%CVE-2024-4563MEDIUMThe Progress MOVEit Automation Configuration Export Function Uses a Cryptographic Method with Insufficient Bit LengthEPSS 0.2%CVE-2024-3892HIGHLocal code execution vulnerability in Telerik UI for WinFormsEPSS 0.2%CVE-2025-8095CRITICALRecoverable obfuscation using the OECH1 prefix encoding in OpenEdgeEPSS 0.2%CVE-2026-7326HIGHCross-site request forgery in Progress MarkLogic Server Admin UIEPSS 0.2%