Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-8037 | Progress | LoadMaster | Progress LoadMaster Command Injection Vulnerability Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints. | 9.6 CNA | 2026-08-07 | 2026-08-10 | Unknown |
| CVE-2024-4885 | Progress | WhatsUp Gold | Progress WhatsUp Gold Path Traversal Vulnerability Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. | 9.8 CNA | 2025-03-03 | 2025-03-24 | Unknown |
| CVE-2024-1212 | Progress | Kemp LoadMaster | Progress Kemp LoadMaster OS Command Injection Vulnerability Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution. | 10.0 CNA | 2024-11-18 | 2024-12-09 | Unknown |
| CVE-2024-6670 | Progress | WhatsUp Gold | Progress WhatsUp Gold SQL Injection Vulnerability Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user. | 9.8 CNA | 2024-09-16 | 2024-10-07 | Known |
| CVE-2024-4358 | Progress | Telerik Report Server | Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access. | 9.8 CNA | 2024-06-13 | 2024-07-04 | Unknown |
| CVE-2023-40044 | Progress | WS_FTP Server | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system. | 10.0 CNA | 2023-10-05 | 2023-10-26 | Known |
| CVE-2023-34362 | Progress | MOVEit Transfer | Progress MOVEit Transfer SQL Injection Vulnerability Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. | 9.8 CISA | 2023-06-02 | 2023-06-23 |
Known
A method to assess 'forgivable' vs 'unforgivable' vulnerabilities
2023 Top Routinely Exploited Vulnerabilities
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime’s Military and Nuclear Programs
North Korea Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs
|
| CVE-2017-9248 | Progress | ASP.NET AJAX and Sitefinity | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), perform cross-site-scripting (XSS) attacks, compromise the ASP.NET ViewState, and/or upload and download files. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-18935 | Progress | Telerik UI for ASP.NET AJAX | Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Known |