Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.40%—Progress Telerik UI FOR Winforms12/2/202517/6/2026
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.
AnalizadaAlta (8.8)0.67%—Progress Telerik Document Processing Libraries12/2/202517/6/2026
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.
AnalizadaAlta (7.8)0.52%—Progress Telerik UI FOR Winui12/2/202517/6/2026
In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaCrítica (9.8)0.74%—Telerik UI FOR WPF16/12/202417/6/2026
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
AnalizadaMedia (6.5)0.43%—Progress Telerik Document Processing Libraries13/11/202417/6/2026
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.
AnalizadaMedia (6.2)0.11%—Progress Telerik Report Server13/11/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this information.
AnalizadaAlta (7.8)0.22%—Progress Telerik UI FOR Winforms13/11/202417/6/2026
In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.
AnalizadaAlta (7.8)0.23%—Telerik UI FOR WPF13/11/202417/6/2026
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
ModificadaAlta (7.8)0.22%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.
AnalizadaAlta (7.2)0.82%—Progress Telerik Report Server9/10/202417/6/2026
In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (8.8)0.62%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.
ModificadaAlta (7.8)0.66%—Progress Telerik Reporting9/10/202417/6/2026
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaMedia (6.5)0.34%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.
AnalizadaAlta (8.8)0.33%—Progress Telerik Reporting9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.
AnalizadaAlta (8.8)0.33%—Progress Telerik Report Server9/10/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.
AnalizadaAlta (7.8)0.25%—Telerik UI FOR WPF25/9/202417/6/2026
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
AnalizadaAlta (7.8)0.74%—Telerik UI FOR WPF25/9/202417/6/2026
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
AnalizadaCrítica (9.8)0.46%—Telerik UI FOR WPF25/9/202417/6/2026
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
AnalizadaCrítica (9.8)0.70%—Telerik UI FOR WPF25/9/202417/6/2026
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
ModificadaCrítica (9.8)2.0%—Progress Telerik Report Server24/7/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.
ModificadaCrítica (9.8)0.86%—Progress Telerik Reporting24/7/202417/6/2026
In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitTelerik Report Server 202429/5/202417/6/2026
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.
AnalizadaMedia (5.3)0.43%—Progress Telerik Report Server15/5/202417/6/2026
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability.
AnalizadaMedia (6.5)0.70%—Progress Telerik Reporting15/5/202417/6/2026
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing.
AnalizadaAlta (8.6)0.27%—Progress Telerik Reporting15/5/202417/6/2026
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.
Orbitaley — Vulnerabilidades