Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Progress Software Corporation — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Progress Software Corporation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software Corporation develops enterprise software solutions, primarily focusing on application development platforms, database management, and IoT connectivity. The company’s product portfolio, including OpenEdge and Telerik components, has historically been associated with a significant volume of security vulnerabilities, currently totaling 86 CVEs. Common flaw categories include remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation errors or improper access controls within legacy codebases. While no single catastrophic incident has defined the company’s public security history, the high CVE count suggests persistent challenges in maintaining secure coding practices across its diverse software suite. Security researchers frequently highlight these issues, urging administrators to apply patches promptly. The firm continues to address these vulnerabilities through regular updates, though the sheer number of recorded exploits indicates a complex attack surface requiring rigorous ongoing maintenance and vigilant configuration management by enterprise users.

CVE ID Title CVSS Severity Published
CVE-2024-46907 WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability — WhatsUp Gold CWE-89 8.8 High 2024-12-02
CVE-2024-46908 WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability — WhatsUp Gold CWE-89 8.8 High 2024-12-02
CVE-2024-7295 Hard-coded credentials used for temporary and cache data encryption — Telerik Report Server CWE-798 7.1 High 2024-11-13
CVE-2024-9999 Multi-Factor Authentication Bypass in Progress WS_FTP Server — WS_FTP Server CWE-303 6.5 Medium 2024-11-12
CVE-2024-9825 The Chef Habitat builder is impacted by Indirect Object reference(IDOR) by deletion of personal access token — Chef Habitat Builder CWE-863 5.4 Medium 2024-10-28
CVE-2024-7763 WhatsUp Gold getReport Missing Authentication Authentication Bypass Vulnerability — WhatsUp Gold CWE-287 9.8 Critical 2024-10-24
CVE-2024-7292 Account Controller allows high count of login attempts — Telerik Report Server CWE-307 7.5 High 2024-10-09
CVE-2024-7294 Uncontrolled resource consumption of anonymous endpoints — Telerik Report Server CWE-400 7.5 High 2024-10-09
CVE-2024-7293 Password policy for new users is not strong enough — Telerik Report Server CWE-521 7.5 High 2024-10-09
CVE-2024-6672 WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerability — WhatsUp Gold CWE-89 8.8 High 2024-08-29
CVE-2024-6671 WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability — WhatsUp Gold CWE-89 9.8 Critical 2024-08-29
CVE-2024-6670 WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability — WhatsUp Gold CWE-89 9.8 Critical 2024-08-29
CVE-2024-7745 Multi-Factor Authentication Bypass in Progress WS_FTP Server — WS_FTP Server CWE-304 6.5 Medium 2024-08-28
CVE-2024-7744 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP Server — WS_FTP Server CWE-22 6.5 Medium 2024-08-28
CVE-2024-6096 Unsafe Deserialization Vulnerability — Telerik Reporting CWE-470 8.8 High 2024-07-24
CVE-2024-6327 Progress Telerik Report Server Deserialization — Telerik Report Server CWE-502 9.9 Critical 2024-07-24
CVE-2024-4882 URL Redirection to Arbitrary Site Exists in Sitefinity — Sitefinity CWE-601 6.1AI Medium AI 2024-07-08
CVE-2024-5019 WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp Gold CWE-22 5.3 Medium 2024-06-25
CVE-2024-5018 WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp Gold CWE-22 5.3 Medium 2024-06-25
CVE-2024-5017 WhatsUp Gold AppProfileImport path traversal vulnerability — WhatsUp Gold CWE-22 6.5 Medium 2024-06-25
CVE-2024-5016 WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability — WhatsUp Gold CWE-502 7.2 High 2024-06-25
CVE-2024-5015 WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerability — WhatsUp Gold CWE-918 7.1 High 2024-06-25
CVE-2024-5014 WhatsUp Gold GetASPReport Server-Side Request Forgery Information Disclosure — WhatsUp Gold CWE-918 7.1 High 2024-06-25
CVE-2024-5013 WhatsUp Gold InstallController Denial-of-Service Vulnerability — WhatsUp Gold CWE-400 7.5 High 2024-06-25
CVE-2024-5012 WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability — WhatsUp Gold CWE-287 8.6 High 2024-06-25
CVE-2024-5011 WhatsUp Gold TestController Chart denial of service vulnerability — WhatsUp Gold CWE-400 7.5 High 2024-06-25
CVE-2024-5010 WhatsUp Gold TestController multiple information disclosure vulnerabilities — WhatsUp Gold CWE-200 7.5 High 2024-06-25
CVE-2024-5009 WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability — WhatsUp Gold CWE-269 8.4 High 2024-06-25
CVE-2024-5008 WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability — WhatsUp Gold CWE-434 8.8 High 2024-06-25
CVE-2024-4885 WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability — WhatsUp Gold CWE-22 9.8 Critical 2024-06-25

This page lists every published CVE security advisory associated with Progress Software Corporation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.