Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

76 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.29%—Progress Telerik Reporting15/5/202417/6/2026
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
AnalizadaMedia (6.7)0.22%—Progress Telerik UI FOR Winforms15/5/202417/6/2026
A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.
AnalizadaAlta (8.8)1.1%—Progress Telerik Reporting20/3/202417/6/2026
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability.
AnalizadaAlta (7.8)0.42%—Progress Telerik Reporting20/3/202417/6/2026
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
AnalizadaAlta (8.8)40%💥 ExploitProgress Telerik Report Server20/3/202417/6/2026
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.
ModificadaAlta (7.8)0.16%—Progress Telerik Test Studio31/1/202417/6/2026
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate…
ModificadaAlta (7.8)0.19%—Progress Telerik Reporting31/1/202417/6/2026
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their…
ModificadaAlta (7.8)0.19%—Progress Telerik Justdecompile31/1/202417/6/2026
In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate…
ModificadaMedia (6.1)0.52%—Kitabisa Teler-waf3/3/202317/6/2026
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. This vulnerability…
ModificadaMedia (6.1)0.54%—Kitabisa Teler-waf2/3/202317/6/2026
teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version 0.1.1 is vulnerable to bypassing common web attack rules when a specific HTML entities payload is used. This vulnerability allows an attacker to execute arbitrary JavaScript code…
ModificadaMedia (5.4)0.42%—Teler Project Teler6/12/202217/6/2026
teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized.…
ModificadaCrítica (9.8)2.3%—Progress Telerik UI FOR Asp.net Ajax11/3/202117/6/2026
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the server and execute code. To exploit, one must use the parameter _TSM_HiddenField_…
ModificadaAlta (7.5)1.4%—Teler Project Teler6/11/202017/6/2026
In teler before version 0.0.1, if you run teler inside a Docker container and encounter `errors.Exit` function, it will cause denial-of-service (`SIGSEGV`) because it doesn't get process ID and process group ID of teler properly to kills. The issue is patched in teler 0.0.1 and 0.0.1-dev5.1.
ModificadaAlta (8.8)1.2%—Telerik Fiddler5/11/202017/6/2026
Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --utility-and-browser --utility-cmd-prefix= and the pathname of a locally installed program. The victim must interactively choose the Open On Browser option. Fixed in…
ModificadaAlta (7.5)1.2%—Telerik UI FOR Silverlight31/3/202017/6/2026
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the…
ModificadaCrítica (9.8)3.0%—Progress Telerik UI FOR Asp.net AjaxTelerik Radchart13/12/201917/6/2026
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitTelerik UI FOR Asp.net Ajax11/12/201917/6/2026
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of…
ModificadaMedia (5.3)1.0%—Progress Telerik Extensions FOR Asp.net MVC8/10/201817/6/2026
Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013.
ModificadaAlta (7.8)1.2%—Telerik JustassemblyTelerik Justdecompile16/8/201817/6/2026
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
AnalizadaCrítica (9.8)78%⚠ Explotación activa💥 ExploitProgress Telerik UI FOR Asp.net Ajax23/8/201714/8/2026
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
AnalizadaCrítica (9.8)84%⚠ Explotación activa💥 ExploitTelerik UI FOR Asp.net Ajax23/8/201717/6/2026
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
AnalizadaCrítica (9.8)75%⚠ Explotación activa💥 ExploitProgress SitefinityTelerik UI FOR Asp.net Ajax3/7/201717/6/2026
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey…
ModificadaMedia (6.1)9.7%💥 ExploitProgress Telerik ReportingProgress Sitefinity CMS22/5/201717/6/2026
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.
ModificadaMedia (6.9)0.50%—Telerik Analytics Monitor Library13/3/201517/6/2026
Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Telerik Analytics Monitor Library before 3.2.125 allow local users to gain privileges via a Trojan horse (a) csunsapi.dll, (b) swift.dll, (c) nfhwcrhk.dll, or (d)…
ModificadaAlta (7.5)4.1%—Progress Telerik UI FOR Asp.net Ajax25/12/201417/6/2026
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value.
Orbitaley — Vulnerabilidades