Vulnerabilities
Vulnerable Software
Progress:  Security Vulnerabilities
In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the report generation process that results in unintended commands being executed on the server.
CVSS Score
8.7
EPSS Score
0.004
Published
2026-04-02
A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actions within their authenticated web session.
CVSS Score
8.5
EPSS Score
0.002
Published
2026-04-02
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
CVSS Score
9.8
EPSS Score
0.584
Published
2026-04-02
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVSS Score
9.1
EPSS Score
0.567
Published
2026-04-02
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-02-25
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
CVSS Score
8.4
EPSS Score
0.265
Published
2026-01-13
OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters
CVSS Score
8.4
EPSS Score
0.265
Published
2026-01-13
A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-01-13
Unverified Password Change vulnerability in Progress MOVEit Transfer on Windows (REST API modules).This issue affects MOVEit Transfer: from 2023.1.0 before 2023.1.3, from 2023.0.0 before 2023.0.8, from 2022.1.0 before 2022.1.11, from 2022.0.0 before 2022.0.10.
CVSS Score
3.7
EPSS Score
0.002
Published
2026-01-07
Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before 2024.1.8, from 2025.0.0 before 2025.0.4.
CVSS Score
5.3
EPSS Score
0.003
Published
2025-11-19


Contact Us

Shodan ® - All rights reserved