Progress maintains a focused but heavily represented portfolio of critical infrastructure and business-continuity products spanning network monitoring, file transfer, content management, and load balancing, with a concentration in widely deployed on-premises and hybrid deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting both the inherent value of these administrative and data-movement tools to attackers and the visibility of disclosed flaws in the security community. The exposure recurs across flagship products such as WhatsUp Gold, MOVEit Transfer, WS_FTP Server, Sitefinity, and LoadMaster through input-handling and access-control weakness classes including cross-site scripting, SQL injection, and path traversal, which are characteristic of web-facing and file-transfer interfaces. Defenders should treat this vendor's security advisories as urgent, particularly for internet-reachable instances of file-transfer and monitoring products, and prioritize inventory and patching of affected versions; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Progress over time
Signals from CVEs in this vendor scope (283 CVEs).
283 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1212CRITICAL Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | Feb 21, 2024 | 9.8 | 99 | YES | YES |
CVE-2023-34362CRITICAL In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found i | Jun 2, 2023 | 9.8 | 99 | YES | YES |
CVE-2024-6670CRITICAL In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password. | Aug 29, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-4885CRITICAL In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The
WhatsUp.ExportUtilities.Export.GetFileWith | Jun 25, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-40044HIGH In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote | Sep 27, 2023 | 8.8 | 98 | YES | YES |
CVE-2017-11357CRITICAL Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or | Aug 23, 2017 | 9.8 | 96 | YES | YES |
CVE-2017-9248CRITICAL Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK | Jul 3, 2017 | 9.8 | 96 | YES | YES |
CVE-2024-2389CRITICAL In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via | Apr 2, 2024 | 9.8 | 91 | NO | YES |
CVE-2023-35708CRITICAL In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identif | Jun 16, 2023 | 9.8 | 88 | NO | YES |
CVE-2023-36934CRITICAL In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerabi | Jul 5, 2023 | 9.1 | 87 | NO | YES |
Signals from CVEs in this vendor scope (283 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Progress.
Media articles that mention a CVE ID that affects a product developed by Progress — matched by CVE ID, not by vendor name.