CVE-2019-18935 is a critical .NET deserialization vulnerability in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX versions through 2019.3.1023. This flaw allows for remote code execution when encryption keys are known, often due to prior vulnerabilities. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. It is actively exploited, listed in the KEV catalog, and has publicly available exploit modules, including in Metasploit, demonstrating significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2011.1.315, <= 2020.1.114CPE matchmatch criteria | cpe:2.3:a:telerik:ui_for_asp.net_ajax:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025GFI Archiver v15.7 Multiple vulnerabilities
Jun 10, 2025