DevExpress develops a portfolio of ASP.NET and web-based UI control libraries and components widely deployed in enterprise application development, where its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code. The recurring exposure reflects the control framework's deserialization and file-access attack surface, with recurrent weakness classes including untrusted deserialization, path traversal, authorization bypass, and type-conversion flaws that are characteristic of managed frameworks handling external input and file operations. Defenders should prioritize this vendor's security updates for internet-facing applications and review applications that accept or expose file-manager and AJAX control inputs; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devexpress over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-2575MEDIUM Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows re | Jun 6, 2014 | 6.5 | 35 | NO | YES |
CVE-2023-35814CRITICAL DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. | Apr 28, 2025 | 9.8 | 29 | NO | NO |
CVE-2021-36483HIGH DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization. | Aug 4, 2021 | 8.8 | 29 | NO | NO |
CVE-2022-28684HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specific | Aug 3, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-35817CRITICAL DevExpress before 23.1.3 allows AsyncDownloader SSRF. | Apr 28, 2025 | 9.8 | 25 | NO | NO |
CVE-2023-35815CRITICAL DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. | Apr 28, 2025 | 9.8 | 25 | NO | NO |
CVE-2022-41479HIGH The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. | Oct 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2015-4670MEDIUM Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrar | Aug 18, 2015 | 6.4 | 18 | NO | NO |
CVE-2023-35816MEDIUM DevExpress before 23.1.3 allows arbitrary TypeConverter conversion. | Apr 28, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devexpress.
Media articles that mention a CVE ID that affects a product developed by Devexpress — matched by CVE ID, not by vendor name.