Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Progress

First CVE: Jan 2, 1999Active for: 28 yearsTotal CVEs: 283
73.2
VTI Score
TOP TARGET

Progress maintains a focused but heavily represented portfolio of critical infrastructure and business-continuity products spanning network monitoring, file transfer, content management, and load balancing, with a concentration in widely deployed on-premises and hybrid deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a frequent tendency toward public exploit availability, reflecting both the inherent value of these administrative and data-movement tools to attackers and the visibility of disclosed flaws in the security community. The exposure recurs across flagship products such as WhatsUp Gold, MOVEit Transfer, WS_FTP Server, Sitefinity, and LoadMaster through input-handling and access-control weakness classes including cross-site scripting, SQL injection, and path traversal, which are characteristic of web-facing and file-transfer interfaces. Defenders should treat this vendor's security advisories as urgent, particularly for internet-reachable instances of file-transfer and monitoring products, and prioritize inventory and patching of affected versions; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
283
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
2.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Progress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 1999
27 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Products(49 total)

Top CVEs

Signals from CVEs in this vendor scope (283 CVEs).

283 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1212CRITICAL
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Feb 21, 20249.899YESYES
CVE-2023-34362CRITICAL
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found i
Jun 2, 20239.899YESYES
CVE-2024-6670CRITICAL
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
Aug 29, 20249.898YESYES
CVE-2024-4885CRITICAL
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWith
Jun 25, 20249.898YESYES
CVE-2023-40044HIGH
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote
Sep 27, 20238.898YESYES
CVE-2017-11357CRITICAL
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or
Aug 23, 20179.896YESYES
CVE-2017-9248CRITICAL
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK
Jul 3, 20179.896YESYES
CVE-2024-2389CRITICAL
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via
Apr 2, 20249.891NOYES
CVE-2023-35708CRITICAL
In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identif
Jun 16, 20239.888NOYES
CVE-2023-36934CRITICAL
In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerabi
Jul 5, 20239.187NOYES
View all 283 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products283 CVEs
34%
48%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local19 (6.7%)
Network220 (77.7%)
Unknown32 (11.3%)
Physical0 (0.0%)
Adjacent Network12 (4.2%)
Attack Complexity
Low235 (83.0%)
High16 (5.7%)
Unknown32 (11.3%)
User Interaction
None191 (67.5%)
Unknown32 (11.3%)
Required60 (21.2%)
Privileges Required
Low73 (25.8%)
High28 (9.9%)
None150 (53.0%)
Unknown32 (11.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (283 CVEs).

CISA KEV
7 CVEs
2.5% of CVEs· 99th percentile
Metasploit
13 CVEs
4.6% of CVEs· 98th percentile
Nuclei
13 CVEs
4.6% of CVEs· 96th percentile
ExploitDB
21 CVEs
7.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Progress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Progress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Progress's Products

View all 3 CNAs →

Top CWEs