Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
377 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 7.7% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp Gold server via the public API. | |
| Analizada | Alta (7.5) | 9.5% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP settings. | |
| Modificada | Media (6.5) | 42% | — | Progress Whatsup Gold | 31/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that can lead to information disclosure. | |
| Aplazada | Media (4.3) | 0.61% | — | Super Progressive WEB AppsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in SuperPWA Super Progressive Web Apps super-progressive-web-apps allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Progressive Web Apps: from n/a through <= 2.2.21. | |
| Analizada | Media (5.3) | 9.5% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage NmAPI.exe to create or change an existing registry value in registry path HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Ipswitch\. | |
| Analizada | Crítica (9.8) | 49% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account. | |
| Analizada | Alta (8.8) | 2.2% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (8.8) | 2.2% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (8.8) | 40% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Alta (8.8) | 2.2% | — | Progress Whatsup Gold | 2/12/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account. | |
| Analizada | Media (5.4) | 0.40% | — | Shafayat Pure CSS Circle Progress BAR | 21/11/2024 | 17/6/2026 | The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.29% | — | Abdullah Nahian Awesome Progress BARAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abdullah Nahian Awesome Progress Bar awesome-progess-bar allows DOM-Based XSS.This issue affects Awesome Progress Bar: from n/a through <= 1.0.13. | |
| Analizada | Media (6.5) | 0.43% | — | Progress Telerik Document Processing Libraries | 13/11/2024 | 17/6/2026 | In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable. | |
| Analizada | Media (6.2) | 0.11% | — | Progress Telerik Report Server | 13/11/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information. | |
| Analizada | Alta (7.8) | 0.22% | — | Progress Telerik UI FOR Winforms | 13/11/2024 | 17/6/2026 | In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability. | |
| Aplazada | Media (5.3) | 0.40% | — | Progress PlannerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.1. | |
| Analizada | Alta (7.5) | 0.61% | — | Progress Whatsup Gold | 24/10/2024 | 17/6/2026 | In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials. | |
| Aplazada | Alta (7.7) | 0.40% | — | Renata Bracichowicz 3D Work IN ProgressAI | 23/10/2024 | 17/6/2026 | Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through <= 1.0.3. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Renata Bracichowicz 3D Work IN ProgressAI | 23/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Upload a Web Shell to a Web Server.This issue affects 3D Work In Progress: from n/a through <= 1.0.3. | |
| Analizada | Crítica (9.8) | 1.2% | — | Progress Loadmaster | 11/10/2024 | 17/6/2026 | Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and… | |
| Modificada | Alta (7.8) | 0.22% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation. | |
| Analizada | Alta (7.2) | 0.82% | — | Progress Telerik Report Server | 9/10/2024 | 17/6/2026 | In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability. | |
| Modificada | Alta (8.8) | 0.62% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability. | |
| Modificada | Alta (7.8) | 0.66% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Analizada | Media (6.5) | 0.34% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting. |