Telerik develops widely deployed UI frameworks and developer tools spanning WPF, ASP.NET AJAX, monitoring, and reverse-engineering utilities that sit deep in enterprise application stacks and developer workflows. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and carry an elevated tendency toward both confirmed in-the-wild exploitation and public exploit availability, with recurring weaknesses in untrusted deserialization, path traversal, command injection, and input validation that reflect the complexity of parsing and object handling in rich application frameworks. Defenders should treat Telerik advisories as high-priority, particularly for internet-facing or supply-chain contexts; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Telerik over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4358CRITICAL In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality v | May 29, 2024 | 9.8 | 99 | YES | YES |
CVE-2019-18935CRITICAL Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys | Dec 11, 2019 | 9.8 | 99 | YES | YES |
CVE-2017-11317CRITICAL Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitr | Aug 23, 2017 | 9.8 | 97 | YES | YES |
CVE-2017-9248CRITICAL Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionK | Jul 3, 2017 | 9.8 | 96 | YES | YES |
CVE-2024-10095CRITICAL In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability. | Dec 16, 2024 | 9.8 | 29 | NO | NO |
CVE-2019-19790CRITICAL Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICON, .JPEG, .PNG, .TIFF, or .WMF | Dec 13, 2019 | 9.8 | 28 | NO | NO |
CVE-2024-7576CRITICAL In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability. | Sep 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-7575CRITICAL In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements. | Sep 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2018-15122HIGH An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object | Aug 16, 2018 | 7.8 | 25 | NO | NO |
CVE-2024-8316HIGH In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability. | Sep 25, 2024 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Telerik.
Media articles that mention a CVE ID that affects a product developed by Telerik — matched by CVE ID, not by vendor name.