Vulnerabilidades en Progress
25 resultadosCVE-2025-10703HIGHImproper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirectEPSS 0.3%CVE-2025-13147MEDIUMExternal Service Interaction (DNS)EPSS 0.2%CVE-2025-2324MEDIUMA MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folderEPSS 0.2%CVE-2025-11235LOWMOVEit Transfer REST API does not require current password in order to initiate the password change processEPSS 0.2%CVE-2024-7346HIGHClient connections using default TLS certificates from OpenEdge may bypass TLS host name validationEPSS 0.2%