Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Telerik

First CVE: Sep 26, 2014Active for: 12 yearsTotal CVEs: 16
68.6
VTI Score
TOP TARGET

Telerik develops widely deployed UI frameworks and developer tools spanning WPF, ASP.NET AJAX, monitoring, and reverse-engineering utilities that sit deep in enterprise application stacks and developer workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and carry an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, with recurring weaknesses in untrusted deserialization, path traversal, command injection, and input validation that reflect the complexity of parsing and object handling in rich application frameworks. Defenders should treat Telerik advisories as high-priority, particularly for internet-facing or supply-chain contexts; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
25.0%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Telerik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 26, 2014
11 years ago
Most Recent CVE
Dec 16, 2024
585 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-4358CRITICAL
In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality v
May 29, 20249.899YESYES
CVE-2019-18935CRITICAL
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys
Dec 11, 20199.899YESYES
CVE-2017-11317CRITICAL
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitr
Aug 23, 20179.897YESYES
CVE-2017-9248CRITICAL
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK
Jul 3, 20179.896YESYES
CVE-2024-10095CRITICAL
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
Dec 16, 20249.829NONO
CVE-2019-19790CRITICAL
Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF
Dec 13, 20199.828NONO
CVE-2024-7576CRITICAL
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
Sep 25, 20249.827NONO
CVE-2024-7575CRITICAL
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
Sep 25, 20249.827NONO
CVE-2018-15122HIGH
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object
Aug 16, 20187.825NONO
CVE-2024-8316HIGH
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.
Sep 25, 20247.823NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
13%
38%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (25.0%)
Network10 (62.5%)
Unknown2 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High0 (0.0%)
Unknown2 (12.5%)
User Interaction
None10 (62.5%)
Unknown2 (12.5%)
Required4 (25.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None13 (81.3%)
Unknown2 (12.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
4 CVEs
25.0% of CVEs· 100th percentile
Metasploit
3 CVEs
18.8% of CVEs· 99th percentile
Nuclei
1 CVE
6.2% of CVEs· 96th percentile
ExploitDB
4 CVEs
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Telerik.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Telerik — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Telerik's Products

View all 3 CNAs →

Top CWEs