Vulnerabilidades em Progress Software Corporation

101 resultados
Análise Vexday

Com 4,65% das CVEs catalogadas confirmadas no CISA KEV, a Progress Software Corporation apresenta uma taxa de exploração ativa 10,3 vezes acima da média geral do catálogo, sinalizando que vulnerabilidades nesse ecossistema atraem atenção consistente de agentes maliciosos. Das 86 CVEs registradas, 19 são de severidade crítica e 5 contam com prova de conceito pública, o que amplia a superfície de risco para organizações que não mantêm ciclos ágeis de atualização. O pior caso ativo hoje é o CVE-2024-4885, com EPSS de 0,9929 — valor extremamente elevado que indica altíssima probabilidade de exploração —, exigindo atenção prioritária de equipes de resposta. O tipo de falha mais recorrente (CWE-79) aponta para problemas persistentes de sanitização de saída, aspecto que deve ser considerado em revisões de configuração e controles de segurança em camada de aplicação.

CVE-2026-7557CRITICALSAML authentication bypass in Progress MarkLogic ServerEPSS 0.3%CVE-2026-8709CRITICALPrivilege escalation in Progress MarkLogic Server REST document patch operationEPSS 0.3%CVE-2026-9193CRITICALPrivilege escalation in Progress MarkLogic Server Hadoop integrationEPSS 0.3%CVE-2024-11625HIGHInformation Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from EPSS 0.3%CVE-2024-4200HIGHProgress Telerik Reporting Local Deserialization VulnerabilityEPSS 0.3%CVE-2023-42658HIGHInSpec Archive Command Vulnerable to Maliciously Crafted ProfileEPSS 0.3%CVE-2024-9825MEDIUMThe Chef Habitat builder is impacted by Indirect Object reference(IDOR) by deletion of personal access tokenEPSS 0.3%CVE-2024-3543MEDIUMLoadMaster Reversible Password Encryption AlgorithmEPSS 0.3%CVE-2024-4202HIGHProgress Telerik Reporting Local Instantiation VulnerabilityEPSS 0.3%CVE-2026-65939MEDIUMWhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.EPSS 0.3%CVE-2025-2572MEDIUMWhatsUp Gold NmConfigurationManager.exe database manipulation vulnerabilityEPSS 0.3%CVE-2026-65937HIGHWhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UIEPSS 0.2%CVE-2026-7327HIGHPrivilege escalation in Progress MarkLogic Server REST API document processingEPSS 0.2%CVE-2024-4563MEDIUMThe Progress MOVEit Automation Configuration Export Function Uses a Cryptographic Method with Insufficient Bit LengthEPSS 0.2%CVE-2024-3892HIGHLocal code execution vulnerability in Telerik UI for WinFormsEPSS 0.2%CVE-2025-8095CRITICALRecoverable obfuscation using the OECH1 prefix encoding in OpenEdgeEPSS 0.2%CVE-2026-9203HIGHServer-side request forgery in Progress MarkLogic ServerEPSS 0.2%CVE-2026-65940MEDIUMWhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.EPSS 0.2%CVE-2026-65938MEDIUMWhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.EPSS 0.2%CVE-2026-7326HIGHCross-site request forgery in Progress MarkLogic Server Admin UIEPSS 0.1%