Progress Telerik Ui For Asp.net Ajax — known CVE vulnerabilities
Every CVE whose affected-product data names Progress Telerik Ui For Asp.net Ajax, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (21)
CVE-2021-28141 — CVSS 9.8 (critical): An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the…
CVE-2019-19790 — CVSS 9.8 (critical): Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF…
CVE-2026-6023 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure…
CVE-2026-13181 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger…
CVE-2026-13185 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout…
CVE-2026-13186 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can…
CVE-2026-13187 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering…
CVE-2026-13190 — CVSS 8.1 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type…
CVE-2025-3600 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an…
CVE-2026-13182 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from…
CVE-2026-6022 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that…
CVE-2026-13183 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through…
CVE-2026-13189 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may…
CVE-2014-2217 — CVSS 7.5 (high): Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2…
CVE-2026-13184 — CVSS 7.5 (high): In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not…
CVE-2026-13192 — CVSS 6.5 (medium): In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature…
CVE-2026-14932 — CVSS 6.5 (medium): In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to…
CVE-2026-13188 — CVSS 5.9 (medium): In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering…
CVE-2026-14865 — CVSS 5.3 (medium): In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling…
CVE-2026-2878 — CVSS 5.3 (medium): In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a…