Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
High

CVE-2019-18935

Disclosure Date: December 11, 2019 (last updated November 08, 2023)
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
Attacker Value
Very High

CVE-2024-4358

Disclosure Date: May 29, 2024 (last updated June 15, 2024)
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
Attacker Value
Unknown

CVE-2017-11317

Disclosure Date: August 23, 2017 (last updated July 04, 2024)
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Attacker Value
Unknown

CVE-2024-10095

Disclosure Date: December 16, 2024 (last updated December 19, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-10013

Disclosure Date: November 13, 2024 (last updated January 13, 2025)
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-10012

Disclosure Date: November 13, 2024 (last updated January 13, 2025)
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-8316

Disclosure Date: September 25, 2024 (last updated October 03, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-7679

Disclosure Date: September 25, 2024 (last updated October 02, 2024)
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Attacker Value
Unknown

CVE-2024-7576

Disclosure Date: September 25, 2024 (last updated October 04, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
Attacker Value
Unknown

CVE-2024-7575

Disclosure Date: September 25, 2024 (last updated October 04, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.