VYPR

Telerik Ui For Asp.net Ajax

by Progress (organisation)

CVEs (23)

  • CVE-2026-14865MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

  • CVE-2026-2878MedFeb 25, 2026
    risk 0.34cvss 5.3epss 0.00

    In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.

  • CVE-2014-2217Dec 25, 2014
    risk 0.00cvss epss 0.04

    Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata…

Page 2 of 2