Skip to main content

Vendor archive

devexpress CVEs

Beta · best-effort

9 CVEs tagged to vendor devexpress0 Critical, 3 High, 3 Medium, 3 Low, 0 Unrated.

CVE-2023-35815

Published Apr 28, 2025

DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-41479

Published Oct 18, 2022

The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28684

Published Aug 3, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specifi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36483

Published Aug 4, 2021

DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4670

Published Aug 18, 2015

Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitra…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1