Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

371 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)49%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
AnalizadaAlta (8.8)2.2%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
AnalizadaAlta (8.8)2.2%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
AnalizadaAlta (8.8)40%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.
AnalizadaAlta (8.8)2.2%—Progress Whatsup Gold2/12/202417/6/2026
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.
AnalizadaMedia (5.4)0.40%—Shafayat Pure CSS Circle Progress BAR21/11/202417/6/2026
The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (6.5)0.29%—Abdullah Nahian Awesome Progress BARAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Abdullah Nahian Awesome Progress Bar awesome-progess-bar allows DOM-Based XSS.This issue affects Awesome Progress Bar: from n/a through <= 1.0.13.
AnalizadaMedia (6.5)0.43%—Progress Telerik Document Processing Libraries13/11/202417/6/2026
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.
AnalizadaMedia (6.2)0.11%—Progress Telerik Report Server13/11/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
AnalizadaAlta (7.8)0.22%—Progress Telerik UI FOR Winforms13/11/202417/6/2026
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
AplazadaMedia (5.3)0.40%—Progress PlannerAI1/11/202417/6/2026
Missing Authorization vulnerability in Progress Planner Progress Planner progress-planner.This issue affects Progress Planner: from n/a through <= 0.9.1.
AnalizadaAlta (7.5)0.61%—Progress Whatsup Gold24/10/202417/6/2026
In WhatsUp Gold versions released before 2024.0.0, an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.
AplazadaAlta (7.7)0.40%—Renata Bracichowicz 3D Work IN ProgressAI23/10/202417/6/2026
Missing Authorization vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 3D Work In Progress: from n/a through <= 1.0.3.
AplazadaCrítica (9.9)0.52%—Renata Bracichowicz 3D Work IN ProgressAI23/10/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Renata Bracichowicz 3D Work In Progress renee-work-in-progress allows Upload a Web Shell to a Web Server.This issue affects 3D Work In Progress: from n/a through <= 1.0.3.
AnalizadaCrítica (9.8)1.2%—Progress Loadmaster11/10/202417/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) From 7.2.49.0 to 7.2.54.12 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.12 and…
ModificadaAlta (7.8)0.22%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
AnalizadaAlta (7.2)0.82%—Progress Telerik Report Server9/10/202417/6/2026
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (8.8)0.62%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (7.8)0.66%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaMedia (6.5)0.34%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
AnalizadaAlta (8.8)0.33%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
AnalizadaAlta (8.8)0.33%—Progress Telerik Report Server9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
AnalizadaMedia (6.8)0.55%—Progress Multi-tenant LoadmasterProgress Loadmaster12/9/202417/6/2026
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) From 7.2.49.0 to 7.2.54.11 (inclusive) 7.2.48.12 and all prior versions Multi-Tenant Hypervisor 7.1.35.11 and…
AnalizadaMedia (6.1)0.29%—Progress Openedge3/9/202417/6/2026
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that…
AnalizadaMedia (4.8)0.16%—Progress Openedge3/9/202417/6/2026
Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. This has been corrected so that default certificates are no longer capable of overriding host name validation and will need to be replaced where full…
Orbitaley — Vulnerabilidades