Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-14932: CWE-321 Use of Hard-coded Cryptographic Key in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-14932
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the obsolete RadChart component's ChartImage.axd handler is vulnerable to unauthenticated file read and deletion of image-extension files within the application directory.

Join the discussion
CVE-2026-14865: CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-14865
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

Join the discussion
CVE-2026-13192: CWE-918 Server-Side Request Forgery (SSRF) in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13192
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of content submitted to the RadEditor PDF export feature may allow an authenticated attacker to trigger server-side requests to arbitrary hosts, resulting in outbound network connections and potential exposure of Windows authentication credentials.

Join the discussion
CVE-2026-13190: CWE-502 Deserialization of Untrusted Data in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13190
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.

Join the discussion
CVE-2026-13189: CWE-36 Absolute Path Traversal in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13189
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.

Join the discussion
CVE-2026-13188: CWE-345 Insufficient Verification of Data Authenticity in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13188
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler request parameters may be tampered with, potentially altering dialog server-side behavior and enabling chained exploitation.

Join the discussion
CVE-2026-13187: CWE-470 Use of Externally-Controlled Input to Select Classes or Code in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13187
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.

Join the discussion
CVE-2026-13186: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13186
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.

Join the discussion
CVE-2026-13185: CWE-502 Deserialization of Untrusted Data in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13185
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.

Join the discussion
CVE-2026-13184: CWE-321 Use of Hard-coded Cryptographic Key in Progress Software Telerik UI for ASP.NET AJAXCVE-2026-13184
0

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Package: pkg:nuget/telerik.ui.for.aspnet.ajax
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses