Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.40% | — | Progress Telerik UI FOR Winforms | 12/2/2025 | 17/6/2026 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory. | |
| Analizada | Alta (8.8) | 0.67% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. | |
| Analizada | Alta (7.8) | 0.52% | — | Progress Telerik UI FOR Winui | 12/2/2025 | 17/6/2026 | In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Analizada | Crítica (9.8) | 0.74% | — | Telerik UI FOR WPF | 16/12/2024 | 17/6/2026 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability. | |
| Analizada | Media (6.5) | 0.43% | — | Progress Telerik Document Processing Libraries | 13/11/2024 | 17/6/2026 | In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable. | |
| Analizada | Media (6.2) | 0.11% | — | Progress Telerik Report Server | 13/11/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information. | |
| Analizada | Alta (7.8) | 0.22% | — | Progress Telerik UI FOR Winforms | 13/11/2024 | 17/6/2026 | In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability. | |
| Analizada | Alta (7.8) | 0.23% | — | Telerik UI FOR WPF | 13/11/2024 | 17/6/2026 | In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability. | |
| Modificada | Alta (7.8) | 0.22% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation. | |
| Analizada | Alta (7.2) | 0.82% | — | Progress Telerik Report Server | 9/10/2024 | 17/6/2026 | In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability. | |
| Modificada | Alta (8.8) | 0.62% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability. | |
| Modificada | Alta (7.8) | 0.66% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Analizada | Media (6.5) | 0.34% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting. | |
| Analizada | Alta (8.8) | 0.33% | — | Progress Telerik Reporting | 9/10/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements. | |
| Analizada | Alta (8.8) | 0.33% | — | Progress Telerik Report Server | 9/10/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts. | |
| Analizada | Alta (7.8) | 0.25% | — | Telerik UI FOR WPF | 25/9/2024 | 17/6/2026 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability. | |
| Analizada | Alta (7.8) | 0.74% | — | Telerik UI FOR WPF | 25/9/2024 | 17/6/2026 | In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Analizada | Crítica (9.8) | 0.46% | — | Telerik UI FOR WPF | 25/9/2024 | 17/6/2026 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability. | |
| Analizada | Crítica (9.8) | 0.70% | — | Telerik UI FOR WPF | 25/9/2024 | 17/6/2026 | In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements. | |
| Modificada | Crítica (9.8) | 2.0% | — | Progress Telerik Report Server | 24/7/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability. | |
| Modificada | Crítica (9.8) | 0.86% | — | Progress Telerik Reporting | 24/7/2024 | 17/6/2026 | In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Telerik Report Server 2024 | 29/5/2024 | 17/6/2026 | In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability. | |
| Analizada | Media (5.3) | 0.43% | — | Progress Telerik Report Server | 15/5/2024 | 17/6/2026 | In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability. | |
| Analizada | Media (6.5) | 0.70% | — | Progress Telerik Reporting | 15/5/2024 | 17/6/2026 | An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing. | |
| Analizada | Alta (8.6) | 0.27% | — | Progress Telerik Reporting | 15/5/2024 | 17/6/2026 | In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability. |