| CVE-2026-7312 | 10 | critical | progress / sitefinity | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4 | 95d ago |
| CVE-2026-9193 | 9.9 | critical | progress / marklogic server | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 | 31d ago |
| CVE-2026-8709 | 9.9 | critical | progress / marklogic server | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Serve | 31d ago |
| CVE-2026-7329 | 9.9 | critical | progress / marklogic server | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress Mark | 31d ago |
| CVE-2026-9192 | 9.8 | critical | progress / marklogic server | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 | 31d ago |
| CVE-2026-7198 | 9.8 | critical | progress / sitefinity | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote | 95d ago |
| CVE-2026-8037exploited | 9.6 | critical | progress / connection manager for objectscale | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated | 93d ago |
| CVE-2026-9195 | 9.3 | critical | progress / marklogic server | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 all | 31d ago |
| CVE-2026-9190 | 9.1 | critical | progress / marklogic server | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0. | 31d ago |
| CVE-2026-7557 | 9.1 | critical | progress / marklogic server | An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress Mar | 31d ago |
| CVE-2026-65941 | 8.8 | high | progress / whatsup gold | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the a | 24d ago |
| CVE-2026-7201 | 8.8 | high | progress / sitefinity | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2 | 95d ago |
| CVE-2026-7195 | 8.8 | high | progress / sitefinity | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4. | 95d ago |
| CVE-2026-15724 | 8.7 | high | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative | 46d ago |
| CVE-2026-7313 | 8.7 | high | progress / sitefinity | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3. | 95d ago |
| CVE-2026-9203 | 8.5 | high | progress / marklogic server | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authent | 31d ago |
| CVE-2026-59688 | 8.4 | high | progress / connection manager for objectscale | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec | 40d ago |
| CVE-2026-59687 | 8.4 | high | progress / connection manager for objectscale | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec | 40d ago |
| CVE-2026-59686 | 8.4 | high | progress / connection manager for objectscale | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec | 40d ago |
| CVE-2026-7327 | 8.1 | high | progress / marklogic server | An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic S | 31d ago |
| CVE-2026-13190 | 8.1 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utiliti | 45d ago |
| CVE-2026-13187 | 8.1 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, po | 45d ago |
| CVE-2026-13186 | 8.1 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persisten | 45d ago |
| CVE-2026-13185 | 8.1 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceM | 45d ago |
| CVE-2026-13181 | 8.1 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName p | 45d ago |
| CVE-2026-9272 | 8.1 | high | progress / flowmon anomaly detection system | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is aut | 65d ago |
| CVE-2026-16138 | 8 | high | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted fil | 19d ago |
| CVE-2026-65937 | 8 | high | progress / whatsup gold | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inje | 24d ago |
| CVE-2026-59690 | 8 | high | progress / connection manager for objectscale | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connec | 40d ago |
| CVE-2026-59689 | 8 | high | progress / connection manager for objectscale | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Con | 40d ago |
| CVE-2026-11903 | 8 | high | progress / moveit transfer | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOV | 59d ago |
| CVE-2026-7326 | 7.5 | high | progress / marklogic server | A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 al | 31d ago |
| CVE-2026-15967 | 7.5 | high | progress / moveit transfer | Insufficient session expiration vulnerability in Progress MOVEit Transfer. | 44d ago |
| CVE-2026-15966 | 7.5 | high | progress / moveit transfer | Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. | 44d ago |
| CVE-2026-10697 | 7.5 | high | progress / moveit transfer | Improper Authentication vulnerability in Progress MOVEit Transfer. | 44d ago |
| CVE-2026-13189 | 7.5 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the s | 45d ago |
| CVE-2026-13184 | 7.5 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and mac | 45d ago |
| CVE-2026-13183 | 7.5 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptog | 45d ago |
| CVE-2026-13182 | 7.5 | high | progress / telerik ui for asp.net ajax | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish dec | 45d ago |
| CVE-2026-10699 | 7.5 | high | progress / moveit transfer | Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modul | 59d ago |
| CVE-2026-8079 | 7.3 | high | progress / flowmon | In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privi | 65d ago |
| CVE-2026-16139 | 7.2 | high | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zone administrato | 19d ago |
| CVE-2026-16137 | 7.2 | high | progress / sharefile storage zones controller | In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform | 19d ago |
| CVE-2026-10698 | 7.2 | high | progress / moveit transfer | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom | 59d ago |
| CVE-2026-15968 | 7.1 | high | progress / moveit transfer | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOV | 44d ago |
| CVE-2026-2514 | 6.1 | | progress / flowmon anomaly detection system | In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with acces | 177d ago |
| CVE-2026-2513 | 6.1 | | progress / flowmon anomaly detection system | A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who cl | 177d ago |