VYPR
Vendor

Progress Telerik

Products
5
CVEs
3
Across products
5
Status
Private

Products

5

Recent CVEs

3
  • CVE-2024-8048HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

  • CVE-2018-15122HigAug 16, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.

  • CVE-2020-11414HigMar 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location…