Vulnerabilities > Progress > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-09 | CVE-2023-34364 | Out-of-bounds Write vulnerability in Progress Datadirect Odbc Oracle Wire Protocol Driver A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. | 9.8 |
2023-06-02 | CVE-2023-34362 | SQL Injection vulnerability in Progress Moveit Cloud and Moveit Transfer In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access to MOVEit Transfer's database. | 9.8 |
2023-04-10 | CVE-2023-29375 | Unrestricted Upload of File with Dangerous Type vulnerability in Progress Sitefinity An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. | 9.8 |
2022-10-12 | CVE-2022-42711 | Cross-site Scripting vulnerability in Progress Whatsup Gold In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. | 9.6 |
2021-08-07 | CVE-2021-38159 | SQL Injection vulnerability in Progress Moveit Transfer In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web application could allow an unauthenticated remote attacker to gain access to the database. | 9.8 |
2020-02-14 | CVE-2020-8612 | Cross-site Scripting vulnerability in multiple products In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS. | 9.0 |
2019-11-26 | CVE-2019-17392 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Progress Sitefinity Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled. | 9.8 |
2018-05-01 | CVE-2018-8939 | Server-Side Request Forgery (SSRF) vulnerability in Progress Whatsup Gold An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). | 9.8 |
2018-05-01 | CVE-2018-8938 | Code Injection vulnerability in Progress Whatsup Gold A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). | 9.8 |
2018-01-24 | CVE-2018-5778 | SQL Injection vulnerability in Progress Whatsup Gold An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). | 9.8 |