Vulnerabilidades em Progress
41 resultadosAnálise Vexday
A Progress acumula 34 vulnerabilidades na base, com 9 publicadas nos últimos 90 dias, indicando pressão contínua de segurança. Nenhuma está sob ataque ativo (KEV) atualmente, mas 6 críticas estão documentadas, com validação de entrada (CWE-20) como fraqueza recorrente. O volume recente de divulgações requer atenção ao ciclo de patching, mas o risco imediato de exploração em massa não está evidente.
CVE-2024-5806CRITICALMOVEit Transfer Authentication Bypass VulnerabilityEPSS 81.5%CVE-2024-7591CRITICALImproper Input Validation vulnerability in Progress LoadMaster allows OS Command InjectionEPSS 43.5%CVE-2024-5805CRITICALMOVEit Gateway Authentication Bypass VulnerabilityEPSS 6.8%CVE-2024-56132HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 6.3%CVE-2024-56131HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 6.1%CVE-2025-1758MEDIUMImproper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects:
* LoadMaster: 7.2.40.0 and aboveEPSS 4.8%CVE-2026-2701CRITICALRCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)EPSS 3.4%CVE-2024-1403CRITICALAuthentication Bypass in OpenEdge Authentication Gateway and AdminServerEPSS 3.3%CVE-2026-2699CRITICALEAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)EPSS 3.2%CVE-2024-8755HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 1.2%CVE-2026-16139HIGHArbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code executionEPSS 0.9%CVE-2026-16138HIGHRemote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO serviceEPSS 0.8%CVE-2026-16137HIGHPath traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones ControllerEPSS 0.7%CVE-2026-10698HIGHTable scope bypass vulnerability in custom reportsEPSS 0.6%CVE-2024-6576HIGHMOVEit Transfer Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-56135HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2024-56134HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2024-56133HIGHImproper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.EPSS 0.6%CVE-2026-8650MEDIUMAuthenticated Path Traversal allows MOVEit admins to view arbitrary system filesEPSS 0.6%CVE-2026-10697HIGHMFA Bypass in MOVEit TransferEPSS 0.6%