progress security advisories
4 threat alerts tracking vulnerabilities and security advisories that affect progress products.
Vulnios monitors progress CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent progress security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2017-11357 — progress — telerik_ui_for_asp.net_ajax
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary co
criticalCVE-2017-11357Critical Vulnerability: CVE-2024-1212 — progress — loadmaster
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
criticalCVE-2024-1212Critical Vulnerability: CVE-2015-8261 — progress — whatsup_gold
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via
criticalCVE-2015-8261Critical Vulnerability: CVE-2015-9245 — progress — openedge
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via
criticalCVE-2015-9245
Track progress exposure across your environment
Vulnios automatically cross-references your asset inventory against new progress CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan