Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Progress — Vulnerabilities & Security Advisories 41

Browse all 41 CVE security advisories affecting Progress. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Progress Software provides enterprise middleware, database management, and application development tools, primarily serving large organizations requiring robust data integration and legacy system support. With twenty-five recorded Common Vulnerabilities and Exposures (CVEs), the vendor’s attack surface has historically been plagued by critical flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues frequently stem from improper input validation and insufficient access controls within its middleware components, such as OpenEdge and DataDirect. Notable incidents involve authenticated attackers exploiting weak authentication mechanisms to gain unauthorized administrative access, potentially leading to complete system compromise. The recurring nature of these defects highlights persistent challenges in securing complex, long-standing software architectures. Consequently, organizations relying on Progress technologies must prioritize rigorous patch management and strict network segmentation to mitigate the risk of exploitation against these known weaknesses.

Found 18 results / 41 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-15968 Stored XSS vulnerability in MOVEit Transfer — MOVEit Transfer CWE-79 7.1 High 2026-07-23
CVE-2026-15967 MOVEit Transfer refresh-token processing does not enforce updated account restrictions — MOVEit Transfer CWE-613 7.5 High 2026-07-23
CVE-2026-15966 Improper CORS handling in MOVEit Transfer — MOVEit Transfer CWE-942 7.5 High 2026-07-23
CVE-2026-10697 MFA Bypass in MOVEit Transfer — MOVEit Transfer CWE-287 7.5 High 2026-07-23
CVE-2026-8801 File Extension Restriction Bypass in MOVEit Transfer — MOVEit Transfer CWE-46 3.5 Low 2026-07-08
CVE-2026-8800 Cross-Org External Token Metadata accessible to AuditUser role — MOVEit Transfer CWE-863 2.7 Low 2026-07-08
CVE-2026-8651 IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer — MOVEit Transfer CWE-290 3.7 Low 2026-07-08
CVE-2026-8650 Authenticated Path Traversal allows MOVEit admins to view arbitrary system files — MOVEit Transfer CWE-23 4.5 Medium 2026-07-08
CVE-2026-8649 Institution scope bypass vulnerability in custom reports — MOVEit Transfer CWE-943 6.4 Medium 2026-07-08
CVE-2026-11903 Stored XSS in MOVEit Transfer Ad Hoc module — MOVEit Transfer CWE-79 8.0 High 2026-07-08
CVE-2026-10699 Memory leak in SFTP service can result in a denial of service in MOVEit Transfer — MOVEit Transfer CWE-401 7.5 High 2026-07-08
CVE-2026-10698 Table scope bypass vulnerability in custom reports — MOVEit Transfer CWE-943 7.2 High 2026-07-08
CVE-2025-11235 MOVEit Transfer REST API does not require current password in order to initiate the password change process — MOVEit Transfer CWE-620 3.7 Low 2026-01-06
CVE-2025-13147 External Service Interaction (DNS) — MOVEit Transfer CWE-918 5.3 Medium 2025-11-19
CVE-2025-10932 AS2 module allows uncontrolled file uploads — MOVEit Transfer CWE-400 8.2 High 2025-10-29
CVE-2025-2324 A MOVEit Transfer user configured as a Shared Account can gain unintended List permissions on a folder — MOVEit Transfer CWE-269 5.9 Medium 2025-03-19
CVE-2024-6576 MOVEit Transfer Privilege Escalation Vulnerability — MOVEit Transfer CWE-287 7.3 High 2024-07-29
CVE-2024-5806 MOVEit Transfer Authentication Bypass Vulnerability — MOVEit Transfer CWE-287 9.1 Critical 2024-06-25

This page lists every published CVE security advisory associated with Progress. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.