Vulnerabilities > Telerik > UI FOR ASP NET Ajax > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-03-11 CVE-2021-28141 Missing Authorization vulnerability in Telerik UI for Asp.Net Ajax 2021.1.224
An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224.
network
low complexity
telerik CWE-862
critical
9.8
2019-12-11 CVE-2019-18935 Deserialization of Untrusted Data vulnerability in Telerik UI for Asp.Net Ajax
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function.
network
low complexity
telerik CWE-502
critical
9.8
2017-08-23 CVE-2017-11317 Inadequate Encryption Strength vulnerability in Telerik UI for Asp.Net Ajax
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
network
low complexity
telerik CWE-326
critical
9.8
2017-08-23 CVE-2017-11357 Unrestricted Upload of File with Dangerous Type vulnerability in Telerik UI for Asp.Net Ajax
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
network
low complexity
telerik CWE-434
critical
9.8
2017-07-03 CVE-2017-9248 Insufficiently Protected Credentials vulnerability in multiple products
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
network
low complexity
telerik progress CWE-522
critical
9.8