Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
376 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 4.8% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 19/3/2025 | 17/6/2026 | Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above | |
| Aplazada | Media (6.9) | 0.36% | — | Icprogress Innovacion Y CualificacionAI | 17/3/2025 | 17/6/2026 | Broken access control vulnerability in the IcProgress Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain sensitive information about other users such as public IP addresses, messages with other users and more. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Icprogreso Innovacion Y CualificacionAI | 17/3/2025 | 17/6/2026 | SQL injection vulnerability in the IcProgreso Innovación y Cualificación plugin. This vulnerability allows an attacker to obtain, update and delete data from the database by injecting an SQL query on the parameters user, id, idGroup, start_date and end_date in the endpoint /report/icprogreso/generar_blocks.php. | |
| Analizada | Media (5.3) | 0.51% | — | Progress Telerik Reporting | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability. | |
| Analizada | Media (6.5) | 0.38% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF. | |
| Analizada | Alta (7.2) | 0.69% | — | Progress Kendo UI FOR VUE | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | |
| Analizada | Media (6.5) | 0.31% | — | Progress Telerik Report Server | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing. | |
| Analizada | Crítica (9.8) | 0.40% | — | Progress Telerik UI FOR Winforms | 12/2/2025 | 17/6/2026 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | |
| Analizada | Alta (7.2) | 0.69% | — | Progress Kendoreact | 12/2/2025 | 17/6/2026 | In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | |
| Analizada | Alta (8.8) | 0.67% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. | |
| Analizada | Alta (7.8) | 0.52% | — | Progress Telerik UI FOR Winui | 12/2/2025 | 17/6/2026 | In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Analizada | Media (6.8) | 0.60% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1… | |
| Analizada | Media (6.8) | 0.60% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12… | |
| Analizada | Media (6.8) | 0.60% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1… | |
| Analizada | Media (6.8) | 6.3% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1… | |
| Analizada | Media (6.8) | 6.1% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12… | |
| Aplazada | Media (6.4) | 0.34% | — | Stormhillmedia MybookprogressAI | 17/1/2025 | 17/6/2026 | The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.5) | 0.23% | — | Harun R Rayhan CC Circle Progress BARAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harun R. Rayhan(thecrazycoder) CC Circle Progress Bar cc-circle-progress-bar allows Stored XSS.This issue affects CC Circle Progress Bar: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Alex Furr Progress TrackerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr Progress Tracker progress-tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through <= 0.9.3. | |
| Analizada | Media (5.4) | 0.21% | — | Node Access Rebuild Progressive Project Node Access Rebuild Progressive | 9/1/2025 | 17/6/2026 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2. | |
| Analizada | Media (5.3) | 0.27% | — | Node Access Rebuild Progressive Project Node Access Rebuild Progressive | 9/1/2025 | 17/6/2026 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2. | |
| Analizada | Alta (8.1) | 0.33% | — | Progress Sitefinity | 7/1/2025 | 17/6/2026 | : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421. | |
| Analizada | Media (4.8) | 0.36% | — | Progress Sitefinity | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through… | |
| Analizada | Media (5.3) | 0.30% | — | Progress Sitefinity | 7/1/2025 | 17/6/2026 | Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421. | |
| Analizada | Crítica (9.6) | 7.7% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. |