Devexpress

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 9
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-35816

    DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.

    Last Modified: Jun 05, 2025
    Published: Apr 28, 2025

    CVE-2023-35817

    DevExpress before 23.1.3 allows AsyncDownloader SSRF.

    Last Modified: Jun 05, 2025
    Published: Apr 28, 2025

    CVE-2023-35814

    DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.

    Last Modified: Jun 05, 2025
    Published: Apr 28, 2025

    CVE-2023-35815

    DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.

    Last Modified: Jun 05, 2025
    Published: Apr 28, 2025

    CVE-2022-41479

    The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19.2.3 does not verify the referenced objects in the /DXR.axd?r= HTTP GET parameter. This leads to an Insecure Direct Object References (IDOR) vulnerability which allows attackers to access the application source code. NOTE: the vendor disputes this because the retrieved source code is only the DevExpress client-side application code that is, of course, intentionally readable by web browsers (a site's custom code and data is never accessible via an IDOR approach).

    Last Modified: May 15, 2025
    Published: Oct 18, 2022
    Items Per Page
    Devexpress Vulnerabilities & Security CVEs | CVE-DB