Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.38%—Progress Telerik Document Processing Libraries12/2/202517/6/2026
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.
AnalizadaAlta (7.2)0.69%—Progress Kendo UI FOR VUE12/2/202517/6/2026
In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
AnalizadaMedia (6.5)0.31%—Progress Telerik Report Server12/2/202517/6/2026
In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing.
AnalizadaCrítica (9.8)0.40%—Progress Telerik UI FOR Winforms12/2/202517/6/2026
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.
AnalizadaAlta (7.2)0.69%—Progress Kendoreact12/2/202517/6/2026
In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.
AnalizadaAlta (8.8)0.67%—Progress Telerik Document Processing Libraries12/2/202517/6/2026
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.
AnalizadaAlta (7.8)0.52%—Progress Telerik UI FOR Winui12/2/202517/6/2026
In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaMedia (6.8)0.60%—Progress Multi-tenant LoadmasterProgress Loadmaster5/2/202517/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1…
AnalizadaMedia (6.8)0.60%—Progress Multi-tenant LoadmasterProgress Loadmaster5/2/202517/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12…
AnalizadaMedia (6.8)0.60%—Progress Multi-tenant LoadmasterProgress Loadmaster5/2/202517/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1…
AnalizadaMedia (6.8)6.3%—Progress Multi-tenant LoadmasterProgress Loadmaster5/2/202517/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1…
AnalizadaMedia (6.8)6.1%—Progress Multi-tenant LoadmasterProgress Loadmaster5/2/202517/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12…
AplazadaMedia (6.4)0.34%—Stormhillmedia MybookprogressAI17/1/202517/6/2026
The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaMedia (6.5)0.23%—Harun R Rayhan CC Circle Progress BARAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harun R. Rayhan(thecrazycoder) CC Circle Progress Bar cc-circle-progress-bar allows Stored XSS.This issue affects CC Circle Progress Bar: from n/a through <= 1.0.0.
AplazadaMedia (6.5)0.37%—Alex Furr Progress TrackerAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr Progress Tracker progress-tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through <= 0.9.3.
AnalizadaMedia (5.4)0.21%—Node Access Rebuild Progressive Project Node Access Rebuild Progressive9/1/202517/6/2026
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.
AnalizadaMedia (5.3)0.27%—Node Access Rebuild Progressive Project Node Access Rebuild Progressive9/1/202517/6/2026
Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.
AnalizadaAlta (8.1)0.33%—Progress Sitefinity7/1/202517/6/2026
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
AnalizadaMedia (4.8)0.36%—Progress Sitefinity7/1/202517/6/2026
Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through…
AnalizadaMedia (5.3)0.30%—Progress Sitefinity7/1/202517/6/2026
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421.
AnalizadaCrítica (9.6)6.8%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
AnalizadaAlta (7.5)9.7%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
ModificadaMedia (6.5)42%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
AplazadaMedia (4.3)0.61%—Super Progressive WEB AppsAI9/12/202417/6/2026
Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21.
AnalizadaMedia (5.3)9.5%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.
Orbitaley — Vulnerabilidades