Where
-Infinity
0

Vendor Risk Score

See how progress compares to other vendors in security performance

View Risk Score →

Software

progress software whatsup gold
28
progress whatsup gold
28
progress moveit transfer
25
progress
16
progress kemp loadmaster
15
progress loadmaster
15
progress ws ftp server
15
progress ipswitch ws ftp server
13
progress software ws_ftp
13
progress telerik ui for asp.net ajax
13
progress software moveit transfer
12
progress ecs connection manager
11
progress moveit waf
11
progress object scale connection manager
9
progress openedge explorer
9
progress enterprise cloud services (ecs)
8
progress flowmon
7
progress moveit automation
7
progress sitefinity
7
progress connection manager for objectscale
6
progress multi-tenant hypervisor
6
progress software moveit automation
6
progress telerik reporting
6
progress progress
5
progress software sitefinity
5
progress flowmon ads
4
progress openedge
4
progress sharefile
3
progress datadirect odbc oracle wire protocol driver
2
progress flowmon anomaly detection system
2
progress hybrid data pipeline
2
progress openedge adminserver
2
progress openedge innovation
2
progress sharefile storage zones controller
2
progress sharefile storage zones controller (szc)
2
progress telerik report server
2
progress telerik ui
2
progress telerik ui for ajax
2
progress telerik ui for winforms
2
progress webspeed
2
progress webspeed messenger
2
progress 4gl compiler
1
progress adminserver
1
progress asp.net ajax and sitefinity
1
progress connection manager for objectscale*
1
progress database
1
progress datadirect connect for jdbc autonomous rest connector
1
progress datadirect connect for jdbc for amazon redshift
1
progress datadirect connect for jdbc for apache cassandra
1
progress datadirect connect for jdbc for apache impala
1

Progress LoadMasterProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API

Risk 73
Severity
8
First published (updated )

Progress LoadMasterProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root

Risk 73
Severity
8
First published (updated )

Progress LoadMasterProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality

Risk 67
Severity
8.4
First published (updated )

Progress LoadMasterProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface

Risk 67
Severity
8.4
First published (updated )

Progress LoadMasterProgress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface

Risk 67
Severity
8.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Progress MOVEit TransferStored XSS vulnerability in MOVEit Transfer

Risk 65
Severity
7.1
First published (updated )

Progress MOVEit TransferMOVEit Transfer refresh-token processing does not enforce updated account restrictions

Risk 86
Severity
9.8
First published (updated )

Progress MOVEit TransferImproper CORS handling in MOVEit Transfer

Risk 86
Severity
9.8
First published (updated )

Progress MOVEit TransferMFA Bypass in MOVEit Transfer

Risk 86
Severity
9.8
First published (updated )

Progress Telerik UI for AJAXUnauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Progress Telerik UI for ASP.NET AJAXXXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX

Risk 27
Severity
5.3
First published (updated )

Progress Telerik UI for ASP.NET AJAXRadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX

Risk 38
Severity
6.5
First published (updated )

Progress Telerik UI for ASP.NET AJAXPersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX

Risk 75
Severity
8.1
First published (updated )

Progress Telerik UI for ASP.NET AJAXSpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX

Risk 43
Severity
7.5
First published (updated )

Progress Telerik UI for AJAXPersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX

Risk 75
Severity
8.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Progress Telerik UI for ASP.NET AJAXRadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX

Risk 43
Severity
7.5
First published (updated )

Progress Telerik UI for ASP.NET AJAXRadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX

Risk 43
Severity
7.5
First published (updated )

Progress Telerik UI for ASP.NET AJAXRadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX

Risk 43
Severity
7.5
First published (updated )

Progress Telerik UI for ASP.NET AJAXRadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX

Risk 75
Severity
8.1
First published (updated )

Progress ShareFile Storage Zones Controller (SZC)Path traversal in Progress ShareFile Storage Zones Controller (SZC)

Risk 59
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Progress MOVEit TransferFile Extension Restriction Bypass in MOVEit Transfer

Risk 61
Severity
9.8
EPSS
0.34%
First published (updated )

Progress MOVEit TransferCross-Org External Token Metadata accessible to AuditUser role

Risk 56
Severity
8.8
EPSS
0.21%
First published (updated )

Progress MOVEit TransferIPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer

Risk 31
Severity
7.5
EPSS
0.21%
First published (updated )

Progress MOVEit TransferAuthenticated Path Traversal allows MOVEit admins to view arbitrary system files

Risk 31
Severity
7.5
EPSS
0.36%
First published (updated )

Progress MOVEit TransferInstitution scope bypass vulnerability in custom reports

Risk 61
Severity
9.8
EPSS
0.23%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Progress MOVEit TransferStored XSS in MOVEit Transfer Ad Hoc module

Risk 71
Severity
8
First published (updated )

Progress MOVEit TransferMemory leak in SFTP service can result in a denial of service in MOVEit Transfer

Risk 43
Severity
7.5
First published (updated )

Progress MOVEit TransferTable scope bypass vulnerability in custom reports

Risk 66
Severity
7.2
First published (updated )

Progress FlowmonUnintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon

Risk 71
Severity
8.7
First published (updated )

Progress Flowmon Anomaly Detection SystemPossibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS

Risk 57
Severity
8.7
EPSS
0.25%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203