Progress
Progress Whatsup Gold: vulnerabilidades y CVE
Progress Whatsup Gold tiene 62 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 13 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE62
Últimos 12 meses5
Críticas13
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-4885 | Crítica (9.8) | 99% | ⚠ Explotación activa | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with… |
| CVE-2024-6670 | Crítica (9.8) | 93% | ⚠ Explotación activa | 29 ago 2024 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65941 | Alta (8.8) | 0.68% | — | 12 ago 2026 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. |
| CVE-2026-65940 | Media (6.8) | 0.35% | — | 12 ago 2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. |
| CVE-2026-65939 | Media (6.8) | 0.38% | — | 12 ago 2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. |
| CVE-2026-65938 | Media (4.3) | 0.25% | — | 12 ago 2026 | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. |
| CVE-2026-65937 | Alta (8) | 0.41% | — | 12 ago 2026 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. |
| CVE-2025-2572 | Media (5.3) | 0.26% | — | 14 abr 2025 | In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. |
| CVE-2024-12108 | Crítica (9.6) | 6.8% | — | 31 dic 2024 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. |
| CVE-2024-12106 | Alta (7.5) | 9.7% | — | 31 dic 2024 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. |
| CVE-2024-12105 | Media (6.5) | 42% | — | 31 dic 2024 | In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure. |
| CVE-2024-8785 | Media (5.3) | 9.5% | — | 2 dic 2024 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path… |
| CVE-2024-46909 | Crítica (9.8) | 49% | — | 2 dic 2024 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account. |
| CVE-2024-46908 | Alta (8.8) | 2.2% | — | 2 dic 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin… |
| CVE-2024-46907 | Alta (8.8) | 2.2% | — | 2 dic 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin… |
| CVE-2024-46906 | Alta (8.8) | 40% | — | 2 dic 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin… |
| CVE-2024-46905 | Alta (8.8) | 2.2% | — | 2 dic 2024 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin… |
| CVE-2024-7763 | Alta (7.5) | 0.61% | — | 24 oct 2024 | In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials. |
| CVE-2024-6672 | Alta (8.8) | 0.71% | — | 29 ago 2024 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password. |
| CVE-2024-6671 | Crítica (9.8) | 19% | — | 29 ago 2024 | In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. |
| CVE-2024-6670 | Crítica (9.8) | 93% | ⚠ Explotación activa | 29 ago 2024 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. |
| CVE-2024-5019 | Alta (7.5) | 0.77% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with… |
| CVE-2024-5018 | Alta (7.5) | 0.77% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the… |
| CVE-2024-5017 | Media (6.5) | 1.6% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure. |
| CVE-2024-5016 | Alta (7.2) | 22% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM. The vulnerability exists in the main… |
| CVE-2024-5015 | Alta (8.8) | 0.53% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access… |
| CVE-2024-5014 | Media (6.5) | 0.48% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form. |
| CVE-2024-5013 | Alta (7.5) | 0.85% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword installation step,… |
| CVE-2024-5012 | Alta (8.6) | 0.45% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored… |
| CVE-2024-5011 | Alta (7.5) | 47% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can lead to denial… |
| CVE-2024-5010 | Alta (7.5) | 70% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specially crafted unauthenticated HTTP request can lead to a disclosure of sensitive information. |
| CVE-2024-5009 | Alta (8.4) | 17% | — | 25 jun 2024 | In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.