CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-86158 HIGH

Missing Authentication in the local .NET backend of Progress Telerik Fiddler Everywhere

CVSS 7.7 EPSS 0.09% Sep 29, 2026
CVE-2026-86157 MEDIUM

Exposure of Privileged IPC Functionality in Progress Telerik Fiddler Everywhere

CVSS 5.6 EPSS 0.12% Sep 29, 2026
CVE-2026-80462 CRITICAL

Privilege Escalation in Progress Chef Automate

CVSS 10.0 EPSS 0.48% Sep 11, 2026
CVE-2026-19219 HIGH

DialogHandler UploadPaths Tampering Vulnerability in Telerik UI for ASP.NET AJAX

CVSS 8.1 EPSS 0.16% Sep 2, 2026
CVE-2026-18672 HIGH

RadImageEditor ClientState Unauthenticated Arbitrary File Read Vulnerability in Telerik UI for ASP.NET AJAX

CVSS 7.5 EPSS 0.36% Sep 2, 2026
CVE-2026-16137 HIGH

Path traversal via unsanitized upload filename leads to arbitrary file write in Progress ShareFile Storage Zones Controller

CVSS 7.2 EPSS 0.74% Aug 17, 2026
CVE-2026-16138 HIGH

Remote code execution via unsafe deserialization in Progress ShareFile Storage Zones Controller's CICO service

CVSS 8.0 EPSS 0.83% Aug 17, 2026
CVE-2026-16139 HIGH

Arbitrary file write via path traversal in Progress ShareFile Storage Zones Controller potentially leading to remote code execution

CVSS 7.2 EPSS 0.94% Aug 17, 2026
CVE-2026-65941 HIGH

WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.

CVSS 8.8 EPSS 0.68% Aug 12, 2026
CVE-2026-65940 MEDIUM

WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on t…

CVSS 6.8 EPSS 0.35% Aug 12, 2026
CVE-2026-65939 MEDIUM

WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.

CVSS 6.8 EPSS 0.38% Aug 12, 2026
CVE-2026-65938 MEDIUM

WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.

CVSS 4.3 EPSS 0.25% Aug 12, 2026
CVE-2026-65937 HIGH

WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI

CVSS 8.0 EPSS 0.41% Aug 12, 2026
CVE-2026-9203 HIGH

Server-side request forgery in Progress MarkLogic Server

CVSS 8.5 EPSS 0.34% Aug 5, 2026
CVE-2026-9195 CRITICAL

Cross-site scripting in Progress MarkLogic Server Query Console

CVSS 9.3 EPSS 0.65% Aug 5, 2026
CVE-2026-9193 CRITICAL

Privilege escalation in Progress MarkLogic Server Hadoop integration

CVSS 9.9 EPSS 0.46% Aug 5, 2026
CVE-2026-9192 CRITICAL

Authentication bypass in Progress MarkLogic Server ODBC App Server

CVSS 9.8 EPSS 0.83% Aug 5, 2026
CVE-2026-9190 CRITICAL

HTTP request smuggling in Progress MarkLogic Server

CVSS 9.1 EPSS 0.74% Aug 5, 2026
CVE-2026-8709 CRITICAL

Privilege escalation in Progress MarkLogic Server REST document patch operation

CVSS 9.9 EPSS 0.46% Aug 5, 2026
CVE-2026-7557 CRITICAL

SAML authentication bypass in Progress MarkLogic Server

CVSS 9.1 EPSS 0.46% Aug 5, 2026
CVE-2026-7329 CRITICAL

Privilege escalation in Progress MarkLogic Server REST query interfaces

CVSS 9.9 EPSS 0.57% Aug 5, 2026
CVE-2026-7327 HIGH

Privilege escalation in Progress MarkLogic Server REST API document processing

CVSS 8.1 EPSS 0.39% Aug 5, 2026
CVE-2026-7326 HIGH

Cross-site request forgery in Progress MarkLogic Server Admin UI

CVSS 8.8 EPSS 0.21% Aug 5, 2026
CVE-2026-59690 HIGH

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation vi…

CVSS 8.0 EPSS 0.26% Jul 27, 2026
CVE-2026-59689 HIGH

Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root

CVSS 8.0 EPSS 0.26% Jul 27, 2026

Showing 1 to 25 CVEs · page 1 (more available)