VendorsProgresswhatsup_goldany version
Vulnerabilities

Progress Whatsup Gold any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

54CVEs
CVE-2015-6005
Multiple cross-site scripting (XSS) vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to inject arbitrary web script or HTML via (1) an SNMP OID object, (2) an SNMP trap message, (3) the View Names field, (4) the Group Names field, (5) the Flow Monitor Credentials field, (6) the Flow Monitor Threshold Name field, (7) the Task Library Name field, (8) the Task Library Description field, (9) the Policy Library Name field, (10) the Policy Library Description field, (11) the Template Library Name field, (12) the Template Library Description field, (13) the System Script Library Name field, (14) the System Script Library Description field, or (15) the CLI Settings Library Description field.
Published 2015-12-27 · Modified
6.9EPSS 0.019
CVE-2026-65939
WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler.
Published 2026-08-12 · Analyzed
6.8EPSS 0.004
CVE-2026-65940
WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server.
Published 2026-08-12 · Analyzed
6.8EPSS 0.004
CVE-2024-12105
WhatsUp Gold - SnmpExtendedActiveMonitor path traversal
Published 2024-12-31 · Modified
6.5EPSS 0.424
CVE-2022-29848
In Progress Ipswitch WhatsUp Gold 17.0.0 through 21.1.1, and 22.0.0, it is possible for an authenticated user to invoke an API transaction that would allow them to read sensitive operating-system attributes from a host that is accessible by the WhatsUp Gold system.
Published 2022-05-11 · Modified
6.5EPSS 0.037
CVE-2015-6004
Multiple SQL injection vulnerabilities in IPSwitch WhatsUp Gold before 16.4 allow remote attackers to execute arbitrary SQL commands via (1) the UniqueID (aka sUniqueID) parameter to WrFreeFormText.asp in the Reports component or (2) the Find Device parameter.
Published 2015-12-27 · Modified
6.5EPSS 0.023
CVE-2024-5017
WhatsUp Gold AppProfileImport path traversal vulnerability
Published 2024-06-25 · Modified
6.5EPSS 0.016
CVE-2023-35759
In Progress WhatsUp Gold before 23.0.0, an SNMP-related application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser, aka XSS.
Published 2023-06-23 · Modified
6.1EPSS 0.021
CVE-2023-6368
WhatsUp Gold Unauthenticated Access to an API Endpoint
Published 2023-12-14 · Modified
5.9EPSS 0.006
CVE-2025-2572
WhatsUp Gold NmConfigurationManager.exe database manipulation vulnerability
Published 2025-04-14 · Analyzed
5.6EPSS 0.003
CVE-2024-4562
WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via HttpMonitorSettings
Published 2024-05-14 · Analyzed
5.4EPSS 0.004
CVE-2022-29846
In Progress Ipswitch WhatsUp Gold 16.1 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to obtain the WhatsUp Gold installation serial number.
Published 2022-05-11 · Modified
5.3EPSS 0.054
CVE-2024-4561
WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via FaviconController
Published 2024-05-14 · Analyzed
5.3EPSS 0.004
CVE-2026-65938
WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API.
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
← Prev2 / 2