VYPR

Vendor CVEs

Telerik

All CVEs

42 total · sorted by risk
  • CVE-2019-18935CriKEVDec 11, 2019
    risk 0.93cvss 9.8epss 1.00

    Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can…

  • CVE-2024-4358CriKEVMay 29, 2024
    risk 0.86cvss 9.8epss 0.97

    In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

  • CVE-2017-11317CriKEVAug 23, 2017
    risk 0.85cvss 9.8epss 0.83

    Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

  • CVE-2017-9248CriKEVJul 3, 2017
    risk 0.85cvss 9.8epss 0.75

    Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection…

  • CVE-2019-19790CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.03

    Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor…

  • CVE-2024-8014HigOct 9, 2024
    risk 0.57cvss 8.8epss 0.01

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.

  • CVE-2020-13661HigNov 5, 2020
    risk 0.57cvss 8.8epss 0.01

    Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --utility-and-browser --utility-cmd-prefix= and the pathname of a locally installed program. The victim must interactively choose…

  • CVE-2024-10095HigDec 16, 2024
    risk 0.55cvss 8.4epss 0.01

    In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2026-13187HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.

  • CVE-2026-13186HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.01

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code…

  • CVE-2026-13185HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.

  • CVE-2026-6023HigApr 22, 2026
    risk 0.53cvss 8.1epss 0.01

    In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers with this state, a server-side remote code…

  • CVE-2025-0332HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.00

    In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.

  • CVE-2024-10013HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-10012HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-7840HigOct 9, 2024
    risk 0.51cvss 7.8epss 0.01

    In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

  • CVE-2024-8316HigSep 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-7679HigSep 25, 2024
    risk 0.51cvss 7.8epss 0.01

    In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.

  • CVE-2024-7576HigSep 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-7575HigSep 25, 2024
    risk 0.51cvss 7.8epss 0.01

    In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.

  • CVE-2024-0833HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to…

  • CVE-2024-0832HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the…

  • CVE-2024-0219HigJan 31, 2024
    risk 0.51cvss 7.8epss 0.00

    In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to…

  • CVE-2019-12097HigJun 3, 2019
    risk 0.51cvss 7.8epss 0.01

    Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privilege escalation by replacing the original EnableLoopback.exe.

  • CVE-2018-15122HigAug 16, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.

  • CVE-2024-1801HigMar 20, 2024
    risk 0.50cvss 7.7epss 0.00

    In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

  • CVE-2026-13184HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload…

  • CVE-2026-13182HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

  • CVE-2020-11414HigMar 31, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location…

  • CVE-2024-3892HigMay 15, 2024
    risk 0.47cvss 7.2epss 0.00

    A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.

  • CVE-2026-13192MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and…

  • CVE-2024-8049MedNov 13, 2024
    risk 0.42cvss 6.5epss 0.00

    In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.

  • CVE-2018-14037MedSep 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Serializer toEditableHtml function in kendo.all.min.js. If the victim accesses the…

  • CVE-2025-6725MedJul 2, 2025
    risk 0.35cvss 5.4epss 0.00

    In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to be re-rendered.

  • CVE-2026-14865MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

  • CVE-2024-6097MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.

  • CVE-2024-4837MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.00

    In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.

  • CVE-2024-11628MedFeb 12, 2025
    risk 0.27cvss 4.1epss 0.01

    In Progress® Telerik® Kendo UI for Vue versions v2.4.0 through v6.0.1, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

  • CVE-2024-12629MedFeb 12, 2025
    risk 0.27cvss 4.1epss 0.01

    In Progress® Telerik® KendoReact versions v3.5.0 through v9.4.0, an attacker can introduce or modify properties within the global prototype chain which can result in denial of service or command injection.

  • CVE-2015-2264Mar 13, 2015
    risk 0.00cvss epss 0.01

    Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Telerik Analytics Monitor Library before 3.2.125 allow local users to gain privileges via a Trojan horse (a) csunsapi.dll, (b)…

  • CVE-2014-2217Dec 25, 2014
    risk 0.00cvss epss 0.04

    Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata…

  • CVE-2014-4958Sep 26, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other versions allows remote attackers to inject arbitrary web script or HTML via CSS expressions in style attributes.