CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere
Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere
Privilege Escalation in Progress Chef Automate
DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX
RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX
Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller
Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service
Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution
WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.
WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on t…
WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.
WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.
WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI
Server-side request forgery in Progress MarkLogic Server
Cross-site scripting in Progress MarkLogic Server Query Console
Privilege escalation in Progress MarkLogic Server Hadoop integration
Authentication bypass in Progress MarkLogic Server ODBC App Server
HTTP request smuggling in Progress MarkLogic Server
Privilege escalation in Progress MarkLogic Server REST document patch operation
SAML authentication bypass in Progress MarkLogic Server
Privilege escalation in Progress MarkLogic Server REST query interfaces
Privilege escalation in Progress MarkLogic Server REST API document processing
Cross-site request forgery in Progress MarkLogic Server Admin UI
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation vi…
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Showing 1 to 25 CVEs · page 1 (more available)