Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.29% | — | Progress Telerik Reporting | 15/5/2024 | 17/6/2026 | In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability. | |
| Analizada | Media (6.7) | 0.22% | — | Progress Telerik UI FOR Winforms | 15/5/2024 | 17/6/2026 | A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system. | |
| Analizada | Alta (8.8) | 1.1% | — | Progress Telerik Reporting | 20/3/2024 | 17/6/2026 | In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability. | |
| Analizada | Alta (7.8) | 0.42% | — | Progress Telerik Reporting | 20/3/2024 | 17/6/2026 | In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability. | |
| Analizada | Alta (8.8) | 40% | 💥 Exploit | Progress Telerik Report Server | 20/3/2024 | 17/6/2026 | In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability. | |
| Modificada | Alta (7.8) | 0.16% | — | Progress Telerik Test Studio | 31/1/2024 | 17/6/2026 | In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate… | |
| Modificada | Alta (7.8) | 0.19% | — | Progress Telerik Reporting | 31/1/2024 | 17/6/2026 | In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their… | |
| Modificada | Alta (7.8) | 0.19% | — | Progress Telerik Justdecompile | 31/1/2024 | 17/6/2026 | In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate… | |
| Modificada | Media (6.1) | 0.52% | — | Kitabisa Teler-waf | 3/3/2023 | 17/6/2026 | teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version v0.2.0 is vulnerable to a bypass attack when a specific case-sensitive hex entities payload with special characters such as CR/LF and horizontal tab is used. This vulnerability… | |
| Modificada | Media (6.1) | 0.54% | — | Kitabisa Teler-waf | 2/3/2023 | 17/6/2026 | teler-waf is a Go HTTP middleware that provides teler IDS functionality to protect against web-based attacks. In teler-waf prior to version 0.1.1 is vulnerable to bypassing common web attack rules when a specific HTML entities payload is used. This vulnerability allows an attacker to execute arbitrary JavaScript code… | |
| Modificada | Media (5.4) | 0.42% | — | Teler Project Teler | 6/12/2022 | 17/6/2026 | teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized.… | |
| Modificada | Crítica (9.8) | 2.3% | — | Progress Telerik UI FOR Asp.net Ajax | 11/3/2021 | 17/6/2026 | An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web.UI.WebResource.axd file. This may allow the attacker to gain unauthorized access to the server and execute code. To exploit, one must use the parameter _TSM_HiddenField_… | |
| Modificada | Alta (7.5) | 1.4% | — | Teler Project Teler | 6/11/2020 | 17/6/2026 | In teler before version 0.0.1, if you run teler inside a Docker container and encounter `errors.Exit` function, it will cause denial-of-service (`SIGSEGV`) because it doesn't get process ID and process group ID of teler properly to kills. The issue is patched in teler 0.0.1 and 0.0.1-dev5.1. | |
| Modificada | Alta (8.8) | 1.2% | — | Telerik Fiddler | 5/11/2020 | 17/6/2026 | Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --utility-and-browser --utility-cmd-prefix= and the pathname of a locally installed program. The victim must interactively choose the Open On Browser option. Fixed in… | |
| Modificada | Alta (7.5) | 1.2% | — | Telerik UI FOR Silverlight | 31/3/2020 | 17/6/2026 | An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the… | |
| Modificada | Crítica (9.8) | 3.0% | — | Progress Telerik UI FOR Asp.net AjaxTelerik Radchart | 13/12/2019 | 17/6/2026 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF on the server through a specially crafted request. NOTE: RadChart was discontinued in 2014 in favor of RadHtmlChart. All RadChart versions… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Telerik UI FOR Asp.net Ajax | 11/12/2019 | 17/6/2026 | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of… | |
| Modificada | Media (5.3) | 1.0% | — | Progress Telerik Extensions FOR Asp.net MVC | 8/10/2018 | 17/6/2026 | Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013. | |
| Modificada | Alta (7.8) | 1.2% | — | Telerik JustassemblyTelerik Justdecompile | 16/8/2018 | 17/6/2026 | An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource. | |
| Analizada | Crítica (9.8) | 78% | ⚠ Explotación activa💥 Exploit | Progress Telerik UI FOR Asp.net Ajax | 23/8/2017 | 14/8/2026 | Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 84% | ⚠ Explotación activa💥 Exploit | Telerik UI FOR Asp.net Ajax | 23/8/2017 | 17/6/2026 | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |
| Analizada | Crítica (9.8) | 75% | ⚠ Explotación activa💥 Exploit | Progress SitefinityTelerik UI FOR Asp.net Ajax | 3/7/2017 | 17/6/2026 | Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey… | |
| Modificada | Media (6.1) | 9.7% | 💥 Exploit | Progress Telerik ReportingProgress Sitefinity CMS | 22/5/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd. | |
| Modificada | Media (6.9) | 0.50% | — | Telerik Analytics Monitor Library | 13/3/2015 | 17/6/2026 | Multiple untrusted search path vulnerabilities in (1) EQATEC.Analytics.Monitor.Win32_vc100.dll and (2) EQATEC.Analytics.Monitor.Win32_vc100-x64.dll in Telerik Analytics Monitor Library before 3.2.125 allow local users to gain privileges via a Trojan horse (a) csunsapi.dll, (b) swift.dll, (c) nfhwcrhk.dll, or (d)… | |
| Modificada | Alta (7.5) | 4.1% | — | Progress Telerik UI FOR Asp.net Ajax | 25/12/2014 | 17/6/2026 | Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and consequently execute arbitrary code, via a full pathname in the UploadID metadata value. |