Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
High
CVE-2019-18935
Disclosure Date: December 11, 2019 (last updated November 08, 2023)
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
5
Attacker Value
Very High
CVE-2024-4358
Disclosure Date: May 29, 2024 (last updated June 15, 2024)
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
2
Attacker Value
Unknown
CVE-2017-11317
Disclosure Date: August 23, 2017 (last updated July 04, 2024)
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
1
Attacker Value
Unknown
CVE-2024-10095
Disclosure Date: December 16, 2024 (last updated December 19, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-10013
Disclosure Date: November 13, 2024 (last updated January 13, 2025)
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-10012
Disclosure Date: November 13, 2024 (last updated January 13, 2025)
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-8316
Disclosure Date: September 25, 2024 (last updated October 03, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-7679
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
0
Attacker Value
Unknown
CVE-2024-7576
Disclosure Date: September 25, 2024 (last updated October 04, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
0
Attacker Value
Unknown
CVE-2024-7575
Disclosure Date: September 25, 2024 (last updated October 04, 2024)
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
0