Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ui For Wpf CRITICAL 9.8
CVE-2024-10095

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulne…

Fix: 24.4.1213+
Fix from $2,300 2024-12-16
Ui For Wpf HIGH 7.8
CVE-2024-10012

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulne…

Fix: 2024.4.1111+
Fix from $1,950 2024-11-13
Ui For Wpf HIGH 7.8
CVE-2024-7679

In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of…

Fix: 2024.3.924+
Fix from $1,950 2024-09-25
Ui For Wpf HIGH 7.8
CVE-2024-8316

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulner…

Fix: 2024.3.924+
Fix from $1,950 2024-09-25
Ui For Wpf CRITICAL 9.8
CVE-2024-7575

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hype…

Fix: 2024.3.924+
Fix from $2,300 2024-09-25
Ui For Wpf CRITICAL 9.8
CVE-2024-7576

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulner…

Fix: 2024.3.924+
Fix from $2,300 2024-09-25
Report Server 2024 CRITICAL 9.8
CVE-2024-4358 KEVEPSS 97%

In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Se…

Fix: after 10.0.24.305
Fix from $2,300 2024-05-29
Fiddler HIGH 8.8
CVE-2020-13661

Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --…

Fix: after 5.0.20202.18177
Fix from $1,950 2020-11-05
Ui For Silverlight HIGH 7.5
CVE-2020-11414

An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a w…

Fix: 2020.1.330+
Fix from $1,950 2020-03-31
Ui For Asp.net Ajax CRITICAL 9.8
CVE-2019-18935 KEVEPSS 100%

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploi…

Fix: after 2020.1.114
Fix from $2,300 2019-12-11
Justassembly HIGH 7.8
CVE-2018-15122

An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by deco…

Mitigation only
Fix from $1,950 2018-08-16
Ui For Asp.net Ajax CRITICAL 9.8
CVE-2017-11317 KEVEPSS 83%

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows rem…

Fix: after 2016.3.1027
Fix from $2,300 2017-08-23
Analytics Monitor Library MEDIUM 6.9
CVE-2015-2264

Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll i…

Fix: after 3.2.122
Fix from $1,600 2015-03-13