Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

377 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)7.7%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API.
AnalizadaAlta (7.5)9.5%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings.
ModificadaMedia (6.5)42%—Progress Whatsup Gold31/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure.
AplazadaMedia (4.3)0.61%—Super Progressive WEB AppsAI9/12/202417/6/2026
Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21.
AnalizadaMedia (5.3)9.5%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\.
AnalizadaCrítica (9.8)49%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
AnalizadaAlta (8.8)2.2%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
AnalizadaAlta (8.8)2.2%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
AnalizadaAlta (8.8)40%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
AnalizadaAlta (8.8)2.2%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.
AnalizadaMedia (5.4)0.40%—Shafayat Pure CSS Circle Progress BAR21/11/202417/6/2026
The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.5)0.29%—Abdullah Nahian Awesome Progress BARAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abdullah Nahian Awesome Progress Bar awesome-progess-bar allows DOM-Based XSS.This issue affects Awesome Progress Bar: from n/a through <= 1.0.13.
AnalizadaMedia (6.5)0.43%—Progress Telerik Document Processing Libraries13/11/202417/6/2026
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.
AnalizadaMedia (6.2)0.11%—Progress Telerik Report Server13/11/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
AnalizadaAlta (7.8)0.22%—Progress Telerik UI FOR Winforms13/11/202417/6/2026
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
AplazadaMedia (5.3)0.40%—Progress PlannerAI1/11/202417/6/2026
Missing Authorization vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.1.
AnalizadaAlta (7.5)0.61%—Progress Whatsup Gold24/10/202417/6/2026
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
AplazadaAlta (7.7)0.40%—Renata Bracichowicz 3D Work IN ProgressAI23/10/202417/6/2026
Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through <= 1.0.3.
AplazadaCrítica (9.9)0.52%—Renata Bracichowicz 3D Work IN ProgressAI23/10/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Upload a Web Shell to a Web Server.This issue affects 3D Work In Progress: from n/a through <= 1.0.3.
AnalizadaCrítica (9.8)1.2%—Progress Loadmaster11/10/202417/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and…
ModificadaAlta (7.8)0.22%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
AnalizadaAlta (7.2)0.82%—Progress Telerik Report Server9/10/202417/6/2026
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (8.8)0.62%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (7.8)0.66%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaMedia (6.5)0.34%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
Orbitaley — Vulnerabilidades