Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Devexpress CRITICAL 9.8
CVE-2023-35817

DevExpress before 23.1.3 allows AsyncDownloader SSRF.

Fix: 21.2.12+
Fix from $2,300 2025-04-28
Devexpress MEDIUM 5.3
CVE-2023-35816

DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

Fix: 21.2.12+
Fix from $1,600 2025-04-28
Devexpress CRITICAL 9.8
CVE-2023-35814

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

Fix: 21.2.12+
Fix from $2,300 2025-04-28
Devexpress CRITICAL 9.8
CVE-2023-35815

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

Fix: 21.2.12+
Fix from $2,300 2025-04-28
Asp.net Web Forms Controls HIGH 7.5
CVE-2022-41479

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /…

No fix yet
Fix from $1,950 2022-10-18
Devexpress HIGH 8.8
CVE-2022-28684

This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit t…

Fix: 18.1.18 / 18.2.17+
Fix from $1,950 2022-08-03
Devexpress HIGH 8.8
CVE-2021-36483

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

Fix: after 21.1
Fix from $1,950 2021-08-04
Ajax Control Toolkit MEDIUM 6.4
CVE-2015-4670

Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote…

Fix: after 15.0
Fix from $1,600 2015-08-18
Aspxfilemanager Control For Webforms And Mvc MEDIUM 6.5
CVE-2014-2575EPSS 9%

Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and…

Fix: after 13.1.9
Fix from $1,600 2014-06-06