Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Progress Software — Vulnerabilities & Security Advisories 90

Browse all 90 CVE security advisories affecting Progress Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software develops enterprise software solutions, primarily focusing on application development platforms, database management, and integration tools for large-scale organizations. Its portfolio includes widely used technologies like OpenEdge and Telerik, which serve as critical infrastructure for business operations. Historically, security audits have identified recurring vulnerability classes within its products, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from input validation errors or improper access controls in legacy components. While no single catastrophic breach has defined the company’s public security history, the accumulation of 55 recorded CVEs highlights persistent challenges in maintaining secure codebases across complex, long-standing software architectures. The company generally responds to disclosures through standard patch cycles, though the volume of findings suggests ongoing efforts to modernize security practices across its diverse product line.

CVE ID Title CVSS Severity Published
CVE-2026-7195 CWE-20: Improper Input Validation in web services in Progress Sitefinity — Sitefinity CWE-20 8.8 High 2026-06-02
CVE-2026-8488 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-770 4.3 Medium 2026-05-20
CVE-2026-8487 Incorrect default permissions vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-276 6.5 Medium 2026-05-20
CVE-2026-8486 Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-770 5.3 Medium 2026-05-20
CVE-2026-8485 Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation — MOVEit Automation CWE-789 5.9 Medium 2026-05-20
CVE-2026-5174 Improper Access Control Vulnerability in Progress MOVEit Automation — MOVEit Automation CWE-20 7.7 High 2026-04-30
CVE-2026-4670 Improper Authentication vulnerability in Progress MOVEit Automation — MOVEit Automation CWE-305 9.8 Critical 2026-04-30
CVE-2026-6023 Deserialization of Untrusted Data Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAX CWE-502 8.1 High 2026-04-22
CVE-2026-6022 Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAX CWE-400 7.5 High 2026-04-22
CVE-2026-4048 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMaster CWE-77 8.4 High 2026-04-20
CVE-2026-3519 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMaster CWE-77 8.4 High 2026-04-20
CVE-2026-3518 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMaster CWE-77 8.4 High 2026-04-20
CVE-2026-3517 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF — LoadMaster CWE-77 8.4 High 2026-04-20
CVE-2026-2737 Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon web application — Flowmon CWE-79 8.3AI High AI 2026-04-02
CVE-2026-3692 Unintended command execution during report generation in Progress Flowmon — Flowmon CWE-78 8.8AI High AI 2026-04-02
CVE-2026-2514 Possibility of unintended actions when viewing maliciously crafted network data in Progress Flowmon ADS web application — Flowmon ADS CWE-79 6.1AI Medium AI 2026-03-12
CVE-2026-2513 Possibility of unintended actions when an administrator clicks a malicious link in the Progress Flowmon ADS web application — Flowmon ADS CWE-79 8.4AI High AI 2026-03-12
CVE-2026-2878 Insufficient Entropy Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAX CWE-331 5.3 Medium 2026-02-25
CVE-2025-6723 Untrusted user data can lead to privilege escalation — Chef Inspec CWE-269 7.8AI High AI 2026-01-30
CVE-2025-13447 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster — LoadMaster 8.4 High 2026-01-13
CVE-2025-13444 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster — LoadMaster 8.4 High 2026-01-13
CVE-2025-13774 SQL injection leading to privilege escalation in Progress Flowmon ADS — Flowmon ADS CWE-89 8.8 High 2026-01-13
CVE-2025-11906 Privilege escalation via writable configuration files in Progress Flowmon — Flowmon CWE-732 6.7 Medium 2025-10-30
CVE-2025-10240 Possibility of unintended actions when a user clicks a malicious link in the Progress Flowmon web application — Flowmon CWE-79 8.8 High 2025-10-09
CVE-2025-10239 Unintended command execution via troubleshooting scripts in Progress Flowmon — Flowmon CWE-78 7.2 High 2025-10-09
CVE-2025-8868 Chef Automate compliance service SQL Injection Vulnerability — Chef Automate CWE-200 9.8 Critical 2025-09-29
CVE-2025-6724 Chef Automate SQL Injection Vulnerability — Chef Automate CWE-89 8.8 High 2025-09-29
CVE-2025-6505 Progress Hybrid Data Pipeline Server 安全漏洞 — Hybrid Data Pipeline 8.1 High 2025-07-29
CVE-2025-6504 Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header — Hybrid Data Pipeline 8.4 High 2025-07-29
CVE-2025-6725 Cross-Site Scripting (XSS) in PdfViewer — Kendo UI for jQuery CWE-79 5.4 Medium 2025-07-02

This page lists every published CVE security advisory associated with Progress Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.