📦

whatsup_gold

Vendor: progress

Actively Exploited 2 CISA KEV List
PoC / Exploits 10 Code Available
Total RCEs 9 Remote Access
Total CVEs 81 Total Indexed
Avg. EPSS 13.33% Exploit Prob.
Latest CVE CVE-2026-65941 Aug 12

Security Vulnerability Index

Page 2 / 9
9.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

EPSS: 48.95%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

EPSS: 2.24%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

EPSS: 2.24%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achieve privilege escalation to the admin account.

EPSS: 40.37%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated lower-privileged user (at least Network Manager permissions required) to achieve privilege escalation to the admin account.

EPSS: 2.24%
9.8 CVSS

In WhatsUp Gold versions released before 2024.0.0,  an Authentication Bypass issue exists which allows an attacker to obtain encrypted user credentials.

EPSS: 0.61%
8.8 CVSS

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an authenticated low-privileged attacker to achieve privilege escalation by modifying a privileged user's password.

EPSS: 0.71%
9.8 CVSS

In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

EPSS: 18.99%
Critical Target
9.8 CVSS
CVE-2024-6670
Exploit Found

In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.

EPSS: 93.00%
5.3 CVSS

In WhatsUp Gold versions released before 2023.1.3,  an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas.Wug.Controllers.SessionController.CachedCSS. This vulnerability allows reading of any file with iisapppool\NmConsole privileges.

EPSS: 0.77%