Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.27% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit… | |
| Analizada | Alta (7.5) | 0.45% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values. | |
| Analizada | Alta (7.5) | 0.50% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers. | |
| Analizada | Alta (8.1) | 0.74% | — | Progress Telerik UI FOR Asp.net Ajax | 22/7/2026 | 6/8/2026 | In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments. | |
| Analizada | Alta (8.7) | 0.52% | — | Progress Sharefile Storage Zones Controller | 21/7/2026 | 3/9/2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |
| Analizada | Crítica (9.8) | 0.55% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. | |
| Analizada | Alta (8.8) | 0.37% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Alta (7.5) | 0.37% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Alta (7.5) | 0.60% | — | Progress Moveit Transfer | 8/7/2026 | 9/7/2026 | Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Crítica (9.8) | 0.46% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. | |
| Analizada | Media (5.4) | 0.41% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer (Ad Hoc module). This issue affects MOVEit Transfer: from 2026.0.0 before 2026.0.1, from 2025.1.0 before 2025.1.4, from 2025.0.0 before 2025.0.8. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |
| Analizada | Alta (7.2) | 0.64% | — | Progress Moveit Transfer | 8/7/2026 | 10/7/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: from 2025.0.0 before 2025.0.8, from 2025.1.0 before 2025.1.4, from 2026.0.0 before 2026.0.1. | |
| Analizada | Alta (8.7) | 0.43% | — | Progress Flowmon Anomaly Detection System | 2/7/2026 | 7/7/2026 | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification. | |
| Analizada | Alta (8.7) | 0.32% | — | Progress Flowmon | 2/7/2026 | 6/7/2026 | In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive… | |
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 4/6/2026 | 1/10/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |
| Analizada | Media (4.9) | 0.51% | — | Progress Sitefinity | 2/6/2026 | 22/7/2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used connect to Sitefinity Insight service. Successful exploitation requires active integration with Sitefinity Insight,… | |
| Analizada | Alta (7.5) | 0.55% | — | Progress Sitefinity | 2/6/2026 | 22/7/2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.8441, 15.3.8500 to 15.3.8531, and 15.4.8600 to 15.4.8630 allows a remote unauthenticated attacker to obtain plain-text… | |
| Analizada | Alta (8.8) | 0.55% | — | Progress Sitefinity | 2/6/2026 | 22/7/2026 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenticated attacker to modify account properties of other users, potentially leading to account compromise. Successful… | |
| Analizada | Crítica (9.8) | 0.65% | — | Progress Sitefinity | 2/6/2026 | 22/7/2026 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in full compromise of confidentiality, integrity, and availability of affected installations. | |
| Analizada | Alta (8.1) | 0.62% | — | Progress Sitefinity | 2/6/2026 | 22/7/2026 | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote unauthenticated attacker to compromise the integrity… | |
| Aplazada | Media (5.9) | 0.24% | — | Emilia Progress PlannerAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Progress Planner allows Stored XSS. This issue affects Progress Planner: from n/a through 1.9.0. | |
| Analizada | Alta (7.5) | 0.45% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Analizada | Alta (7.5) | 0.34% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Data. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Flooding. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. |