Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.38% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF. | |
| Analizada | Alta (7.2) | 0.69% | — | Progress Kendo UI FOR VUE | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | |
| Analizada | Media (6.5) | 0.31% | — | Progress Telerik Report Server | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Report Server, versions prior to 2025 Q1 (11.0.25.211) when using the older .NET Framework implementation, communication of non-sensitive information between the service agent process and app host process occurs over an unencrypted tunnel, which can be subjected to local network traffic sniffing. | |
| Analizada | Crítica (9.8) | 0.40% | — | Progress Telerik UI FOR Winforms | 12/2/2025 | 17/6/2026 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | |
| Analizada | Alta (7.2) | 0.69% | — | Progress Kendoreact | 12/2/2025 | 17/6/2026 | In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection. | |
| Analizada | Alta (8.8) | 0.67% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. | |
| Analizada | Alta (7.8) | 0.52% | — | Progress Telerik UI FOR Winui | 12/2/2025 | 17/6/2026 | In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Analizada | Media (6.8) | 0.60% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1… | |
| Analizada | Media (6.8) | 0.60% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12… | |
| Analizada | Media (6.8) | 0.60% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1… | |
| Analizada | Media (6.8) | 6.3% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions ECS All prior versions to 7.2.60.1… | |
| Analizada | Media (6.8) | 6.1% | — | Progress Multi-tenant LoadmasterProgress Loadmaster | 5/2/2025 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12… | |
| Aplazada | Media (6.4) | 0.34% | — | Stormhillmedia MybookprogressAI | 17/1/2025 | 17/6/2026 | The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (6.5) | 0.23% | — | Harun R Rayhan CC Circle Progress BARAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Harun R. Rayhan(thecrazycoder) CC Circle Progress Bar cc-circle-progress-bar allows Stored XSS.This issue affects CC Circle Progress Bar: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Alex Furr Progress TrackerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Furr Progress Tracker progress-tracker allows DOM-Based XSS.This issue affects Progress Tracker: from n/a through <= 0.9.3. | |
| Analizada | Media (5.4) | 0.21% | — | Node Access Rebuild Progressive Project Node Access Rebuild Progressive | 9/1/2025 | 17/6/2026 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2. | |
| Analizada | Media (5.3) | 0.27% | — | Node Access Rebuild Progressive Project Node Access Rebuild Progressive | 9/1/2025 | 17/6/2026 | Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2. | |
| Analizada | Alta (8.1) | 0.33% | — | Progress Sitefinity | 7/1/2025 | 17/6/2026 | : Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421. | |
| Analizada | Media (4.8) | 0.36% | — | Progress Sitefinity | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During CMS Backend (adminstrative section) Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Progress Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through… | |
| Analizada | Media (5.3) | 0.30% | — | Progress Sitefinity | 7/1/2025 | 17/6/2026 | Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through 15.0.8229, from 15.1.8300 through 15.1.8327, from 15.2.8400 through 15.2.8421. | |
| Analizada | Crítica (9.6) | 6.8% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | |
| Analizada | Alta (7.5) | 9.7% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. | |
| Modificada | Media (6.5) | 42% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure. | |
| Aplazada | Media (4.3) | 0.61% | — | Super Progressive WEB AppsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21. | |
| Analizada | Media (5.3) | 9.5% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\. |