CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2023-35817 CRITICAL

DevExpress before 23.1.3 allows AsyncDownloader SSRF.

CVSS 9.8 EPSS 0.48% Apr 28, 2025
CVE-2023-35816 MEDIUM

DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

CVSS 5.3 EPSS 0.55% Apr 28, 2025
CVE-2023-35815 CRITICAL

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

CVSS 9.8 EPSS 0.60% Apr 28, 2025
CVE-2023-35814 CRITICAL

DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

CVSS 9.8 EPSS 0.60% Apr 28, 2025
CVE-2022-41479 HIGH

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r=…

CVSS 7.5 EPSS 1.20% Oct 18, 2022
CVE-2022-28684 HIGH

This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulner…

CVSS 8.8 EPSS 3.65% Aug 3, 2022
CVE-2021-36483 HIGH

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

CVSS 8.8 EPSS 2.90% Aug 4, 2021
CVE-2015-4670 MEDIUM

Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers…

CVSS 6.4 EPSS 1.91% Aug 18, 2015
CVE-2014-2575 MEDIUM

Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x be…

CVSS 6.5 EPSS 8.92% Jun 6, 2014

Showing 1 to 9 CVEs · page 1