Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.68% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account. | |
| Analizada | Media (6.8) | 0.35% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. | |
| Analizada | Media (6.8) | 0.38% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root. | |
| Analizada | Media (4.3) | 0.25% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions. | |
| Analizada | Alta (8) | 0.41% | — | Progress Whatsup Gold | 12/8/2026 | 2/9/2026 | In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content. | |
| Analizada | Media (5.3) | 0.26% | — | Progress Whatsup Gold | 14/4/2025 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.3, a database manipulation vulnerability allows an unauthenticated attacker to modify the contents of WhatsUp.dbo.WrlsMacAddressGroup. | |
| Analizada | Crítica (9.6) | 7.7% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | |
| Analizada | Alta (7.5) | 9.5% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. | |
| Modificada | Media (6.5) | 42% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure. | |
| Analizada | Media (5.3) | 9.5% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\. | |
| Analizada | Crítica (9.8) | 49% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account. | |
| Analizada | Alta (8.8) | 2.2% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (8.8) | 2.2% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (8.8) | 40% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (8.8) | 2.2% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (7.5) | 0.61% | — | Progress Whatsup Gold | 24/10/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials. | |
| Analizada | Alta (8.8) | 0.71% | — | Progress Whatsup Gold | 29/8/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password. | |
| Analizada | Crítica (9.8) | 19% | 💥 Exploit | Progress Whatsup Gold | 29/8/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | |
| Analizada | Crítica (9.8) | 93% | ⚠ Explotación activa💥 Exploit | Progress Whatsup Gold | 29/8/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | |
| Modificada | Alta (7.5) | 0.77% | — | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges. | |
| Modificada | Alta (7.5) | 0.77% | — | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.Wug.Controllers.SessionController.LoadNMScript. This allows allows reading of any file from the applications web-root directory . | |
| Modificada | Media (6.5) | 1.6% | — | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure. | |
| Modificada | Alta (7.2) | 22% | — | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as SYSTEM. The vulnerability exists in the main message processing routines NmDistributed.DistributedServiceBehavior.OnMessage for server and… | |
| Modificada | Alta (8.8) | 0.53% | — | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper Access Control vulnerability. This can be used to escalate privileges to Admin. | |
| Modificada | Media (6.5) | 0.48% | — | Progress Whatsup Gold | 25/6/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve ASP reports from an HTML form. |