Progress
Progress Telerik Reporting: vulnerabilidades y CVE
Progress Telerik Reporting tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6097 | Media (5.3) | 0.51% | — | 12 feb 2025 | In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability. |
| CVE-2024-8048 | Alta (7.8) | 0.22% | — | 9 oct 2024 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation. |
| CVE-2024-8014 | Alta (8.8) | 0.62% | — | 9 oct 2024 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability. |
| CVE-2024-7840 | Alta (7.8) | 0.66% | — | 9 oct 2024 | In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements. |
| CVE-2024-7294 | Media (6.5) | 0.34% | — | 9 oct 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting. |
| CVE-2024-7293 | Alta (8.8) | 0.33% | — | 9 oct 2024 | In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements. |
| CVE-2024-6096 | Crítica (9.8) | 0.86% | — | 24 jul 2024 | In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability. |
| CVE-2024-4357 | Media (6.5) | 0.70% | — | 15 may 2024 | An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing. |
| CVE-2024-4202 | Alta (8.6) | 0.27% | — | 15 may 2024 | In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability. |
| CVE-2024-4200 | Alta (7.8) | 0.29% | — | 15 may 2024 | In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability. |
| CVE-2024-1856 | Alta (8.8) | 1.1% | — | 20 mar 2024 | In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization vulnerability. |
| CVE-2024-1801 | Alta (7.8) | 0.42% | — | 20 mar 2024 | In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability. |
| CVE-2024-0832 | Alta (7.8) | 0.19% | — | 31 ene 2024 | In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present,… |
| CVE-2017-9140 | Media (6.1) | 9.7% | — | 22 may 2017 | Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary… |