43 Total CVEs
43 AI Analyzed
1 CISA KEV
9 Critical

Profile

2.3% ended up actively exploited 1 of 43 added to CISA KEV
21% rated critical (CVSS 9.0+) 9 critical, 34 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

38 CVEs in the last 12 months

Products

  • MarkLogic Server6
  • Telerik UI for ASP.NET AJAX6
  • Sitefinity5
  • LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF4
  • ADC Products4
  • Software MOVEit2
  • Flowmon ADS1
  • Flowmon1

11 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-43 of 43 CVEs
CVE-2026-9272
Analyzed
8.7
Progress Software Flowmon ADS

In Progress Flowmon ADS versions prior to 12

2026-07-03
CVE-2026-9203
Analyzed
8.5
Progress Software MarkLogic Server

A server-side request forgery vulnerability in Progress MarkLogic Server before 11

2026-08-06
CVE-2026-9193
Analyzed
9.9
Progress Software MarkLogic Server

Progress Software MarkLogic Server contains an improper privilege management flaw in its Hadoop integration, enabling authenticated users to escalate...

2026-08-06
CVE-2026-9192
Analyzed
9.8
Progress Software MarkLogic Server

Progress MarkLogic Server contains an authentication bypass vulnerability in the ODBC App Server, allowing unauthenticated attackers to execute querie...

2026-08-06
CVE-2026-8709
Analyzed
9.9
Progress Software MarkLogic Server

Progress MarkLogic Server contains an improper privilege management vulnerability in its REST API, allowing low-privileged users to perform unauthoriz...

2026-08-06
CVE-2026-8079
Analyzed
8.7
Progress Software Flowmon

In Progress Flowmon versions prior to 12

2026-07-03
CVE-2026-8037
KEV Analyzed
9.5
Progress Software LoadMaster

Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands...

2026-08-08
CVE-2026-7329
Analyzed
9.9
Progress Software MarkLogic Server

Progress MarkLogic Server contains an improper privilege management vulnerability in its query interfaces allowing authenticated users with low-privil...

2026-08-06
CVE-2026-7327
Analyzed
8.1
Progress Software MarkLogic Server

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11

2026-08-06
CVE-2026-7313
Analyzed
8.7
Progress Software Sitefinity

CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8

2026-06-04
CVE-2026-7312
Analyzed
10
Progress Software Sitefinity

Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitef...

2026-06-03
CVE-2026-7201
Analyzed
8.8
Progress Software Sitefinity

CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15

2026-06-03
CVE-2026-7198
Analyzed
9.8
Progress Software Sitefinity

Improper access control in Progress Sitefinity web services allows unauthenticated attackers to access restricted content and fully compromise the ins...

2026-06-03
CVE-2026-7195
Analyzed
8.8
Progress Software Sitefinity

CWE-20: Improper Input Validation in web services in Progress Sitefinity 14

2026-06-03
CVE-2026-65941
Analyzed
8.8
Progress Software WhatsUp Gold

In WhatsUp Gold versions released before 2026

2026-08-13
CVE-2026-6023
Analyzed
8.1
Progress Software Multiple Products

In Progress® Telerik® UI for AJAX versions 2024

2026-04-22
CVE-2026-59690
Analyzed
8
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, Multi Tenant

A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi...

2026-07-28
CVE-2026-59689
Analyzed
8
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allo...

2026-07-28
CVE-2026-59688
Analyzed
8.4
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows...

2026-07-28
CVE-2026-59687
Analyzed
8.4
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows...

2026-07-28
CVE-2026-59686
Analyzed
8.4
Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows...

2026-07-28
CVE-2026-5174
Analyzed
7.7
Progress Software Software MOVEit

Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation

2026-05-01
CVE-2026-4670
Analyzed
9.8
Progress Software Software MOVEit

An authentication bypass vulnerability in Progress Software MOVEit Automation allows unauthorized access to the application.

2026-05-01
CVE-2026-4048
Analyzed
8.4
Progress Software ADC Products

OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to exe...

2026-04-21
CVE-2026-3519
Analyzed
8.4
Progress Software ADC Products

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” per...

2026-04-21
CVE-2026-3518
Analyzed
8.4
Progress Software ADC Products

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to ex...

2026-04-21
CVE-2026-3517
Analyzed
8.4
Progress Software ADC Products

OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” pe...

2026-04-21
CVE-2026-19219
Analyzed
8.1
Progress Software Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file brow...

2026-09-04
CVE-2026-13190
Analyzed
8.1
Progress Software Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13187
Analyzed
8.1
Progress Software Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13186
Analyzed
8.1
Progress Software Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13185
Analyzed
8.1
Progress Software Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2026-13181
Analyzed
8.1
Progress Software Telerik UI for ASP.NET AJAX

In Progress® Telerik® UI for AJAX prior to v2026

2026-07-24
CVE-2025-8868
Analyzed
9.8
Progress Software Multiple Products

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricte...

2025-09-29
CVE-2025-7388
Analyzed
8.4
Progress Software Multiple Products

It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing authenticated users to inject a...

2025-09-04
CVE-2025-6724
Analyzed
8.8
Progress Software Multiple Products

In Progress Chef Automate, versions earlier than 4

2025-09-29
CVE-2025-6505
Analyzed
8.1
Progress Software Multiple Products

Unauthorized access and impersonation can occur in versions 4

2025-07-29
CVE-2025-6504
Analyzed
8.4
Progress Software Multiple Products

In HDP Server versions below 4

2025-07-29
CVE-2025-13774
Analyzed
8.8
Progress Software Multiple Products

A vulnerability exists in Progress Flowmon ADS versions prior to 12

2026-01-14
CVE-2025-13447
Analyzed
8.4
Progress Software Multiple Products

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” per...

2026-01-14
CVE-2025-13444
Analyzed
8.4
Progress Software Multiple Products

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” per...

2026-01-14
CVE-2025-10240
Analyzed
8.8
Progress Software Multiple Products

A vulnerability exists in the Progress Flowmon web application prior to version 12

2025-10-09
CVE-2025-10239
Analyzed
7.2
Progress Software Multiple Products

In Flowmon versions prior to 12

2025-10-09