Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Progress Software Corporation — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Progress Software Corporation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software Corporation develops enterprise software solutions, primarily focusing on application development platforms, database management, and IoT connectivity. The company’s product portfolio, including OpenEdge and Telerik components, has historically been associated with a significant volume of security vulnerabilities, currently totaling 86 CVEs. Common flaw categories include remote code execution, cross-site scripting, and privilege escalation, often stemming from input validation errors or improper access controls within legacy codebases. While no single catastrophic incident has defined the company’s public security history, the high CVE count suggests persistent challenges in maintaining secure coding practices across its diverse software suite. Security researchers frequently highlight these issues, urging administrators to apply patches promptly. The firm continues to address these vulnerabilities through regular updates, though the sheer number of recorded exploits indicates a complex attack surface requiring rigorous ongoing maintenance and vigilant configuration management by enterprise users.

CVE ID Title CVSS Severity Published
CVE-2024-4884 WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerability — WhatsUp Gold CWE-77 9.8 Critical 2024-06-25
CVE-2024-4883 WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability — WhatsUp Gold CWE-77 9.8 Critical 2024-06-25
CVE-2024-4358 Registration Authentication Bypass Vulnerability — Telerik Report Server CWE-290 9.8 Critical 2024-05-29
CVE-2024-4563 The Progress MOVEit Automation Configuration Export Function Uses a Cryptographic Method with Insufficient Bit Length — MOVEit Automation CWE-327 6.1 Medium 2024-05-22
CVE-2024-4200 Progress Telerik Reporting Local Deserialization Vulnerability — Telerik Reporting CWE-502 7.7 High 2024-05-15
CVE-2024-4202 Progress Telerik Reporting Local Instantiation Vulnerability — Telerik Reporting CWE-94 7.7 High 2024-05-15
CVE-2024-3892 Local code execution vulnerability in Telerik UI for WinForms — Telerik UI for WinForms CWE-94 7.2 High 2024-05-15
CVE-2024-4562 WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via HttpMonitorSettings — WhatsUp Gold CWE-918 5.4 Medium 2024-05-14
CVE-2024-4561 WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via FaviconController — WhatsUp Gold CWE-918 4.2 Medium 2024-05-14
CVE-2024-3544 LoadMaster Hardcoded SSH Key — LoadMaster CWE-798 7.5 High 2024-05-02
CVE-2024-3543 LoadMaster Reversible Password Encryption Algorithm — LoadMaster CWE-257 6.4 Medium 2024-05-02
CVE-2024-1856 Progress Telerik Reporting Remote Deserialization Vulnerability — Telerik Reporting CWE-502 8.5 High 2024-03-20
CVE-2024-1801 Progress Telerik Reporting Local Deserialization Vulnerability — Telerik Reporting CWE-502 7.7 High 2024-03-20
CVE-2024-1800 Progress Telerik Report Server Deserialization — Telerik Report Server CWE-502 9.9 Critical 2024-03-20
CVE-2024-1636 Potential Cross-Site Scripting (XSS) in the page editing area — Sitefinity CWE-79 8.0 High 2024-02-28
CVE-2024-1632 Incorrect access control in the Sitefinity backend — Sitefinity CWE-284 8.8 High 2024-02-28
CVE-2023-40052 Progress Application Server (PAS) for OpenEdge Denial of Service — OpenEdge CWE-119 7.5 High 2024-01-18
CVE-2023-40051 Progress Application Server (PAS) for OpenEdge File Upload via Directory Traversal — OpenEdge CWE-434 9.1 Critical 2024-01-18
CVE-2024-0396 Missing Server-Side Input Validation in HTTP Parameter — MOVEit Transfer CWE-20 7.1 High 2024-01-17
CVE-2023-6784 Potential Use of the Sitefinity System for Distribution of Phishing Emails — Sitefinity CWE-20 4.7 Medium 2023-12-20
CVE-2023-6368 WhatsUp Gold Unauthenticated Access to an API Endpoint — WhatsUp Gold CWE-306 5.9 Medium 2023-12-14
CVE-2023-6595 WhatsUp Gold Unauthenticated Access to an API Endpoint — WhatsUp Gold CWE-306 7.5 High 2023-12-14
CVE-2023-6367 WhatsUp Gold Stored Cross-Site Scripting (XSS) via Roles — WhatsUp Gold CWE-79 7.6 High 2023-12-14
CVE-2023-6366 WhatsUp Gold Stored Cross-Site Scripting (XSS) via Alert Center — WhatsUp Gold CWE-79 7.6 High 2023-12-14
CVE-2023-6365 WhatsUp Gold Stored Cross-Site Scripting (XSS) via Device Groups — WhatsUp Gold CWE-79 7.6 High 2023-12-14
CVE-2023-6364 WhatsUp Gold Stored Cross-Site Scripting (XSS) via Dashboard — WhatsUp Gold CWE-79 7.6 High 2023-12-14
CVE-2023-6218 MOVEit Transfer Group Admin Privilege Escalation — MOVEit Transfer CWE-269 7.2 High 2023-11-29
CVE-2023-6217 MOVEit Transfer XSS via MOVEit Gateway — MOVEit Transfer CWE-79 7.1 High 2023-11-29
CVE-2023-42659 WS_FTP Server Arbitrary File Upload — WS_FTP Server CWE-434 9.1 Critical 2023-11-07
CVE-2023-42658 InSpec Archive Command Vulnerable to Maliciously Crafted Profile — Chef InSpec CWE-94 8.8 High 2023-10-31

This page lists every published CVE security advisory associated with Progress Software Corporation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.