VendorsProgresswhatsup_goldall versions
Vulnerabilities

Progress Whatsup Gold

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2024-4885
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
Published 2024-06-25 · Analyzed
9.8KEVEPSS 0.993
CVE-2024-6670
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
Published 2024-08-29 · Analyzed
9.8KEVEPSS 0.930
CVE-2024-4883
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
Published 2024-06-25 · Modified
9.8EPSS 0.645
CVE-2024-46909
WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability
Published 2024-12-02 · Analyzed
9.8EPSS 0.489
CVE-2024-4884
WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerability
Published 2024-06-25 · Modified
9.8EPSS 0.243
CVE-2024-6671
WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability
Published 2024-08-29 · Analyzed
9.8EPSS 0.190
CVE-2024-8785
WhatsUp Gold Registry Overwrite Remote Code Execution Vulnerability
Published 2024-12-02 · Analyzed
9.8EPSS 0.095
CVE-2015-8261
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.
Published 2016-01-08 · Modified
9.81 PoCEPSS 0.036
CVE-2018-8938
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands and code on the WhatsUp Gold server.
Published 2018-05-01 · Modified
9.8EPSS 0.023
CVE-2018-5777
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP server that could allow attackers to execute arbitrary commands on the TFTP server via unspecified vectors.
Published 2018-01-24 · Modified
9.8EPSS 0.017
CVE-2018-8939
An SSRF issue was discovered in NmAPI.exe in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can submit specially crafted requests via the NmAPI executable to (1) gain unauthorized access to the WhatsUp Gold system, (2) obtain information about the WhatsUp Gold system, or (3) execute remote commands.
Published 2018-05-01 · Modified
9.8EPSS 0.014
CVE-2018-5778
An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands via unspecified vectors.
Published 2018-01-24 · Modified
9.8EPSS 0.011
CVE-2024-7763
WhatsUp Gold getReport Missing Authentication Authentication Bypass Vulnerability
Published 2024-10-24 · Analyzed
9.8EPSS 0.006
CVE-2024-12108
WhatsUp Gold - Public API signing key rotation issue
Published 2024-12-31 · Analyzed
9.6EPSS 0.068
CVE-2022-42711
In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.
Published 2022-10-12 · Modified
9.6EPSS 0.011
CVE-2024-12106
WhatsUp Gold - LDAP configuration interface leading to allowing attacker to configure LDAP settings without authentication
Published 2024-12-31 · Analyzed
9.4EPSS 0.097
CVE-2024-46906
WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability
Published 2024-12-02 · Analyzed
8.8EPSS 0.404
CVE-2024-5008
WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability
Published 2024-06-25 · Modified
8.8EPSS 0.173
CVE-2024-46905
WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation Vulnerability
Published 2024-12-02 · Analyzed
8.8EPSS 0.022
CVE-2024-46907
WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability
Published 2024-12-02 · Analyzed
8.8EPSS 0.022
CVE-2024-46908
WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability
Published 2024-12-02 · Analyzed
8.8EPSS 0.022
CVE-2016-1000000
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
Published 2016-10-06 · Modified
8.8EPSS 0.013
CVE-2024-6672
WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerability
Published 2024-08-29 · Analyzed
8.8EPSS 0.007
CVE-2026-65941
WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service.
Published 2026-08-12 · Analyzed
8.8EPSS 0.007
CVE-2024-5015
WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerability
Published 2024-06-25 · Modified
8.8EPSS 0.005
CVE-2024-5012
WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability
Published 2024-06-25 · Modified
8.6EPSS 0.004
CVE-2024-5009
WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability
Published 2024-06-25 · Modified
8.4EPSS 0.174
CVE-2026-65937
WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI
Published 2026-08-12 · Analyzed
8.0EPSS 0.004
CVE-2007-2602
Buffer overflow in MIBEXTRA.EXE in Ipswitch WhatsUp Gold 11 allows attackers to cause a denial of service (application crash) or execute arbitrary code via a long MIB filename argument. NOTE: If there is not a common scenario under which MIBEXTRA.EXE is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.
Published 2007-05-11 · Modified
7.8EPSS 0.035
CVE-2023-6367
WhatsUp Gold Stored Cross-Site Scripting (XSS) via Roles
Published 2023-12-14 · Modified
7.6EPSS 0.005
CVE-2023-6364
WhatsUp Gold Stored Cross-Site Scripting (XSS) via Dashboard
Published 2023-12-14 · Modified
7.6EPSS 0.005
CVE-2023-6365
WhatsUp Gold Stored Cross-Site Scripting (XSS) via Device Groups
Published 2023-12-14 · Modified
7.6EPSS 0.005
CVE-2023-6366
WhatsUp Gold Stored Cross-Site Scripting (XSS) via Alert Center
Published 2023-12-14 · Modified
7.6EPSS 0.005
CVE-2024-5010
WhatsUp Gold TestController multiple information disclosure vulnerabilities
Published 2024-06-25 · Modified
7.5EPSS 0.700
CVE-2004-0798
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.
Published 2004-08-27 · Modified
7.52 PoCEPSS 0.626
CVE-2022-29847
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.
Published 2022-05-11 · Modified
7.5EPSS 0.576
CVE-2024-5011
WhatsUp Gold TestController Chart denial of service vulnerability
Published 2024-06-25 · Modified
7.5EPSS 0.471
CVE-2012-2601
SQL injection vulnerability in WrVMwareHostList.asp in Ipswitch WhatsUp Gold 15.02 allows remote attackers to execute arbitrary SQL commands via the sGroupList parameter.
Published 2012-08-15 · Modified
7.51 PoCEPSS 0.029
CVE-2024-5013
WhatsUp Gold InstallController Denial-of-Service Vulnerability
Published 2024-06-25 · Modified
7.5EPSS 0.008
CVE-2023-6595
WhatsUp Gold Unauthenticated Access to an API Endpoint
Published 2023-12-14 · Modified
7.5EPSS 0.008
1 / 2Next →