VendorsProgressloadmasterall versions
Vulnerabilities

Progress Loadmaster

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2024-1212
LoadMaster Pre-Authenticated OS Command Injection
Published 2024-02-21 · Analyzed
10.0KEVEPSS 0.954
CVE-2026-8037
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Published 2026-06-04 · Analyzed
9.8KEVEPSS 0.996
CVE-2024-8755
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Published 2024-10-11 · Analyzed
9.8EPSS 0.012
CVE-2024-2448
LoadMaster Command Injection Vulnerability
Published 2024-03-22 · Analyzed
8.8EPSS 0.554
CVE-2014-5287
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
Published 2020-01-08 · Modified
8.81 PoCEPSS 0.080
CVE-2025-1758
Improper Input Validation vulnerability in Progress LoadMaster allows : Buffer OverflowThis issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
Published 2025-03-19 · Analyzed
8.8EPSS 0.048
CVE-2025-13447
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster
Published 2026-01-13 · Analyzed
8.4EPSS 0.272
CVE-2025-13444
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster
Published 2026-01-13 · Analyzed
8.4EPSS 0.272
CVE-2026-3518
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Published 2026-04-20 · Analyzed
8.4EPSS 0.169
CVE-2026-3517
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Published 2026-04-20 · Analyzed
8.4EPSS 0.155
CVE-2024-56132
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Published 2025-02-05 · Analyzed
8.4EPSS 0.063
CVE-2024-56131
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Published 2025-02-05 · Analyzed
8.4EPSS 0.061
CVE-2026-3519
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Published 2026-04-20 · Analyzed
8.4EPSS 0.021
CVE-2026-4048
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
Published 2026-04-20 · Analyzed
8.4EPSS 0.021
CVE-2026-59686
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
Published 2026-07-27 · Analyzed
8.4EPSS 0.014
CVE-2026-59688
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality
Published 2026-07-27 · Analyzed
8.4EPSS 0.007
CVE-2026-59687
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface
Published 2026-07-27 · Analyzed
8.4EPSS 0.007
CVE-2024-56134
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Published 2025-02-05 · Analyzed
8.4EPSS 0.006
CVE-2024-56135
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Published 2025-02-05 · Analyzed
8.4EPSS 0.006
CVE-2024-56133
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.
Published 2025-02-05 · Analyzed
8.4EPSS 0.006
CVE-2024-6658
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.
Published 2024-09-12 · Analyzed
8.4EPSS 0.006
CVE-2026-59690
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API
Published 2026-07-27 · Analyzed
8.0EPSS 0.002
CVE-2026-59689
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root
Published 2026-07-27 · Analyzed
8.0EPSS 0.002
CVE-2024-2449
LoadMaster Cross-Site Request Forgery (CSRF)
Published 2024-03-22 · Analyzed
7.5EPSS 0.129
CVE-2024-3544
LoadMaster Hardcoded SSH Key
Published 2024-05-02 · Analyzed
7.5EPSS 0.004
CVE-2024-3543
LoadMaster Reversible Password Encryption Algorithm
Published 2024-05-02 · Analyzed
7.5EPSS 0.003