Vulnerabilidades en Progress
38 resultadosAnálisis Vexday
A Progress acumula 34 vulnerabilidades na base, com 9 publicadas nos últimos 90 dias, indicando pressão contínua de segurança. Nenhuma está sob ataque ativo (KEV) atualmente, mas 6 críticas estão documentadas, com validação de entrada (CWE-20) como fraqueza recorrente. O volume recente de divulgações requer atenção ao ciclo de patching, mas o risco imediato de exploração em massa não está evidente.
CVE-2026-10699HIGHMemory leak in SFTP service can result in a denial of service in MOVEit TransferEPSS 0.3%CVE-2026-15724HIGHPath traversal in Progress ShareFile Storage Zones Controller (SZC)EPSS 0.3%CVE-2024-11627MEDIUM: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 thrEPSS 0.3%CVE-2025-10702HIGHImproper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirectEPSS 0.3%CVE-2025-10703HIGHImproper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirectEPSS 0.3%CVE-2026-10697HIGHMFA Bypass in MOVEit TransferEPSS 0.3%CVE-2026-11903HIGHStored XSS in MOVEit Transfer Ad Hoc moduleEPSS 0.3%CVE-2024-7654HIGHUnauthenticated Content Injection in OpenEdge Management web interface via ActiveMQ discovery serviceEPSS 0.3%CVE-2025-13147MEDIUMExternal Service Interaction (DNS)EPSS 0.3%CVE-2026-8649MEDIUMInstitution scope bypass vulnerability in custom reportsEPSS 0.3%CVE-2025-2324MEDIUMA MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folderEPSS 0.2%CVE-2026-8651LOWIPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit TransferEPSS 0.2%CVE-2026-8800LOWCross-Org External Token Metadata accessible to AuditUser roleEPSS 0.2%CVE-2026-15967HIGHMOVEit Transfer refresh-token processing does not enforce updated account restrictionsEPSS 0.2%CVE-2026-15966HIGHImproper CORS handling in MOVEit TransferEPSS 0.2%CVE-2025-11235LOWMOVEit Transfer REST API does not require current password in order to initiate the password change processEPSS 0.2%CVE-2026-15968HIGHStored XSS vulnerability in MOVEit TransferEPSS 0.2%CVE-2024-7346HIGHClient connections using default TLS certificates from OpenEdge may bypass TLS host name validationEPSS 0.2%