Progress Software Corporation
First CVE: Sep 20, 2023Active for: 3 years
207
CVEs Published
More CVEs Published than 80% of tracked CNAs
51.8
Avg CVEs / Year
More Avg CVEs / Year than 85% of tracked CNAs
7.6
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked CNAs
2.4%
In CISA KEV
Higher KEV Rate than 92% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Progress Software Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 20, 2023
2 years ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by Progress Software Corporation as a CNA, regardless of affected vendor or product.
207 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4358CRITICAL In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality v | May 29, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-1212CRITICAL Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | Feb 21, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-6670CRITICAL In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | Aug 29, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-4885CRITICAL In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The
WhatsUp.ExportUtilities.Export.GetFileWith | Jun 25, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-40044HIGH In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote | Sep 27, 2023 | 8.8 | 98 | YES | YES |
CVE-2024-2389CRITICAL In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via | Apr 2, 2024 | 9.8 | 91 | NO | YES |
CVE-2024-5806CRITICAL Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11 | Jun 25, 2024 | 9.8 | 85 | NO | YES |
CVE-2026-2699CRITICAL Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration a | Apr 2, 2026 | 9.8 | 81 | NO | YES |
CVE-2026-8037CRITICAL OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster applian | Jun 4, 2026 | 9.8 | 80 | NO | YES |
CVE-2024-4883CRITICAL In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve t | Jun 25, 2024 | 9.8 | 67 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA207 CVEs
29%
53%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local19 (9.2%)
Network172 (83.1%)
Unknown4 (1.9%)
Physical0 (0.0%)
Adjacent Network11 (5.3%)
Attack Complexity
Low188 (90.8%)
High15 (7.2%)
Unknown4 (1.9%)
User Interaction
None165 (79.7%)
Unknown4 (1.9%)
Required35 (16.9%)
Privileges Required
Low63 (30.4%)
High31 (15.0%)
None109 (52.7%)
Unknown4 (1.9%)
Exploit Exposure
Signals from CVEs in this cna scope (207 CVEs).
CISA KEV
5 CVEs
2.4% of CVEs· 92nd percentile
Metasploit
7 CVEs
3.4% of CVEs· 95th percentile
Nuclei
11 CVEs
5.3% of CVEs· 93rd percentile
ExploitDB
1 CVE
0.5% of CVEs· 77th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Progress Software Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Progress Software Corporation as a CNA — matched by CVE ID, not by organization name.