Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.43% | — | Progress Moveit Automation | 20/5/2026 | 23/7/2026 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This issue affects MOVEit Automation: before 2025.0.11, from 2025.1.0 before 2025.1.7. | |
| Analizada | Alta (8.8) | 0.50% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Analizada | Crítica (9.8) | 0.73% | — | Progress Telerik UI FOR Asp.net Ajax | 22/4/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code execution is possible. | |
| Analizada | Alta (7.5) | 0.49% | — | Progress Telerik UI FOR Asp.net Ajax | 22/4/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion. | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process. | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command | |
| Pendiente de análisis | Crítica (9.1) | 0.22% | — | Progress OpenedgeAI | 14/4/2026 | 7/10/2026 | The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all… | |
| Pendiente de análisis | Alta (8.2) | 0.33% | — | Progress OpenedgeAI | 14/4/2026 | 7/10/2026 | A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-level access to the server through the adopted authority of the AdminServer process itself. The delegated authority of the AdminServer could allow its users the ability to read arbitrary files on the… | |
| Analizada | Alta (8.7) | 0.57% | — | Progress Flowmon | 2/4/2026 | 6/7/2026 | In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server. | |
| Analizada | Alta (8.5) | 0.25% | — | Progress Flowmon | 2/4/2026 | 6/7/2026 | A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |
| Analizada | Alta (8.8) | 3.4% | — | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | |
| Analizada | Crítica (9.8) | 3.2% | 💥 Exploit | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. | |
| Aplazada | Alta (7.1) | 0.18% | — | Progressionstudios VayvoAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ProgressionStudios Vayvo vayvo-progression allows Reflected XSS.This issue affects Vayvo: from n/a through < 6.8. | |
| Analizada | Alta (8.6) | 0.18% | — | Progress Flowmon Anomaly Detection System | 12/3/2026 | 3/9/2026 | In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, a vulnerability exists whereby an adversary with access to Flowmon monitoring ports may craft malicious network data that, when processed by Flowmon ADS and viewed by an authenticated user, could result in unintended actions being executed in the user's… | |
| Analizada | Alta (8.6) | 0.16% | — | Progress Flowmon Anomaly Detection System | 12/3/2026 | 3/9/2026 | A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session. | |
| Aplazada | Media (4.3) | 0.24% | — | Reading ProgressbarAI | 12/3/2026 | 17/6/2026 | The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (8.1) | 0.58% | — | Themerex ProgressAIPHPAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Progress progress allows PHP Local File Inclusion.This issue affects Progress: from n/a through <= 1.2. | |
| Analizada | Media (5.9) | 0.30% | — | Progress Telerik UI FOR Asp.net Ajax | 25/2/2026 | 17/6/2026 | In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering. | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR Objectscale*Progress ECS Connection ManagerProgress LoadmasterProgress Moveit WAF+1 | 13/1/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Media (6.8) | 27% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Hypervisor+1 | 13/1/2026 | 10/8/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters | |
| Analizada | Alta (8.8) | 0.47% | — | Progress Flowmon Anomaly Detection System | 13/1/2026 | 17/6/2026 | A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands. | |
| Analizada | Alta (7.5) | 0.21% | — | Progress Moveit Transfer | 7/1/2026 | 17/6/2026 | Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10. |