CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
DevExpress before 23.1.3 allows AsyncDownloader SSRF. |
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion. |
DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. |
DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of DevExpress. Authentication is required to exploit this vulnerability. The specific flaw exists within the SafeBinaryFormat...Show more |
DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization. |