Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Progress Software — Vulnerabilities & Security Advisories 90

Browse all 90 CVE security advisories affecting Progress Software. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software develops enterprise software solutions, primarily focusing on application development platforms, database management, and integration tools for large-scale organizations. Its portfolio includes widely used technologies like OpenEdge and Telerik, which serve as critical infrastructure for business operations. Historically, security audits have identified recurring vulnerability classes within its products, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from input validation errors or improper access controls in legacy components. While no single catastrophic breach has defined the company’s public security history, the accumulation of 55 recorded CVEs highlights persistent challenges in maintaining secure codebases across complex, long-standing software architectures. The company generally responds to disclosures through standard patch cycles, though the volume of findings suggests ongoing efforts to modernize security practices across its diverse product line.

CVE ID Title CVSS Severity Published
CVE-2025-3600 Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX — Telerik UI for ASP.NET AJAX 7.5 High 2025-05-14
CVE-2024-11629 Telerik Document Processing RTF Export of Arbitrary File Path — Progress® Telerik® Document Processing Libraries CWE-552 7.1 High 2025-02-12
CVE-2024-11628 Prototype Pollution in Progress® Telerik® Kendo UI for Vue — Progress® Telerik® Kendo UI for Vue CWE-1321 4.1 Medium 2025-02-12
CVE-2024-11343 Telerik Document Processing Path Traversal — Telerik Document Processing Libraries CWE-22 8.3 High 2025-02-12
CVE-2024-12629 Prototype Pollution in Progress® Telerik® KendoReact — Telerik KendoReact CWE-1321 4.1 Medium 2025-02-12
CVE-2025-0332 Progress UI for WinForms decompression path traversal vulnerability — Progress® Telerik® UI for WinForms CWE-22 7.8 High 2025-02-12
CVE-2025-0556 Telerik Report Server Clear Text Transmission of Agent Commands — Telerik Report Server CWE-319 8.8 High 2025-02-12
CVE-2024-12251 Improper neutralization special element in hyperlinks — Telerik UI for WinUI CWE-77 7.8 High 2025-02-12
CVE-2024-10095 Progress UI for WPF format provider unsafe deserialization vulnerability — Telerik UI for WPF CWE-502 8.4 High 2024-12-16
CVE-2024-8049 Telerik Document Processing Improper Handling of Memory Resources — Telerik Document Processing Libraries CWE-834 6.5 Medium 2024-11-13
CVE-2024-10012 Progress UI for WPF format provider unsafe deserialization vulnerability — Telerik UI for WPF CWE-502 7.8 High 2024-11-13
CVE-2024-10013 Progress UI for WinForms format provider unsafe deserialization vulnerability — Telerik UI for WinForms CWE-502 7.8 High 2024-11-13
CVE-2024-8015 Telerik Report Server Insecure Type Resolution — Telerik Reporting CWE-470 9.1 Critical 2024-10-09
CVE-2024-7840 Improper neutralization special element in hyperlinks — Telerik Reporting CWE-77 7.8 High 2024-10-09
CVE-2024-8048 Telerik Reporting Insecure Expression Evaluation — Telerik Reporting CWE-470 7.8 High 2024-10-09
CVE-2024-8014 Telerik Reporting EntityDataSource Insecure Type Resolution — Telerik Reporting CWE-470 8.8 High 2024-10-09
CVE-2024-8316 Progress UI for WPF format provider unsafe deserialization vulnerability — Telerik UI for WPF CWE-502 7.8 High 2024-09-25
CVE-2024-7576 Progress UI for WPF format provider unsafe deserialization vulnerability — Telerik UI for WPF CWE-502 7.8 High 2024-09-25
CVE-2024-7575 Improper neutralization special element in hyperlinks — Telerik UI for WPF CWE-77 7.8 High 2024-09-25
CVE-2024-7679 Improper neutralization special element in hyperlinks — Telerik UI for WinForms CWE-77 7.8 High 2024-09-25
CVE-2024-4837 Trust Boundary Violation Vulnerability — Telerik Report Server CWE-200 5.3 Medium 2024-05-15
CVE-2024-4357 XML External Entity Processing Information Disclosure — Telerik Report Server CWE-611 6.5 Medium 2024-05-15
CVE-2024-2389 Flowmon Unauthenticated Command Injection Vulnerability — Flowmon CWE-78 10.0 Critical 2024-04-02
CVE-2024-2449 LoadMaster Cross-Site Request Forgery (CSRF) — LoadMaster CWE-352 7.5 High 2024-03-22
CVE-2024-2448 LoadMaster Command Injection Vulnerability — LoadMaster CWE-78 8.4 High 2024-03-22
CVE-2024-2291 MOVEit Transfer Logging Bypass Vulnerability — MOVEit Transfer CWE-778 4.3 Medium 2024-03-20
CVE-2024-1212 LoadMaster Pre-Authenticated OS Command Injection — LoadMaster CWE-78 10.0 Critical 2024-02-21
CVE-2024-0833 Privilege Elevation via Telerik Test Studio — Telerik Test Studio CWE-269 7.8 High 2024-01-31
CVE-2024-0832 Privilege Elevation via Telerik Reporting Installer — Telerik Reporting CWE-269 7.8 High 2024-01-31
CVE-2024-0219 Privilege Elevation via Telerik JustDecompile Installer — Telerik JustDecompile CWE-269 7.8 High 2024-01-31

This page lists every published CVE security advisory associated with Progress Software. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.