Progress

Telerik Ui For Asp.Net Ajax

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 02.09.2026 10:35:51
  • Zuletzt bearbeitet 08.09.2026 19:20:25

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the ...

  • EPSS 0.36%
  • Veröffentlicht 02.09.2026 10:31:43
  • Zuletzt bearbeitet 08.09.2026 19:20:25

In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is returned by the control's image cache, potentially exposing file contents outs...

  • EPSS 0.35%
  • Veröffentlicht 22.07.2026 13:46:45
  • Zuletzt bearbeitet 06.08.2026 17:41:50

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.

  • EPSS 0.26%
  • Veröffentlicht 22.07.2026 13:45:21
  • Zuletzt bearbeitet 06.08.2026 17:45:37

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

  • EPSS 0.42%
  • Veröffentlicht 22.07.2026 13:44:14
  • Zuletzt bearbeitet 06.08.2026 17:47:06

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound net...

  • EPSS 0.49%
  • Veröffentlicht 22.07.2026 13:43:12
  • Zuletzt bearbeitet 06.08.2026 17:49:14

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.

  • EPSS 0.36%
  • Veröffentlicht 22.07.2026 13:42:19
  • Zuletzt bearbeitet 06.08.2026 17:52:29

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.

  • EPSS 0.16%
  • Veröffentlicht 22.07.2026 13:41:29
  • Zuletzt bearbeitet 06.08.2026 18:03:21

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.

  • EPSS 0.34%
  • Veröffentlicht 22.07.2026 13:40:21
  • Zuletzt bearbeitet 06.08.2026 18:04:40

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.

  • EPSS 0.53%
  • Veröffentlicht 22.07.2026 13:39:14
  • Zuletzt bearbeitet 06.08.2026 18:06:22

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserializ...