Microsoft / Asp.net Core
39 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-45591 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | Jun 9, 2026 |
| CVE-2026-40372 | ASP.NET Core Elevation of Privilege Vulnerability | CRITICAL | 9.1 | Apr 21, 2026 |
| CVE-2026-26130 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | Mar 10, 2026 |
| CVE-2025-55315 | ASP.NET Security Feature Bypass Vulnerability | CRITICAL | 9.9 | Oct 14, 2025 |
| CVE-2025-26682 | ASP.NET Core and Visual Studio Denial of Service Vulnerability | HIGH | 7.5 | Apr 8, 2025 |
| CVE-2025-24070 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | HIGH | 7.8 | Mar 11, 2025 |
| CVE-2024-21404 | .NET Denial of Service Vulnerability | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2024-21386 | .NET Denial of Service Vulnerability | HIGH | 7.5 | Feb 13, 2024 |
| CVE-2023-36038 | ASP.NET Core Denial of Service Vulnerability | HIGH | 8.2 | Nov 14, 2023 |
| CVE-2023-36558 | ASP.NET Core Security Feature Bypass Vulnerability | MEDIUM | 6.2 | Nov 14, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-38180 KEV | .NET and Visual Studio Denial of Service Vulnerability | HIGH | 7.5 | Aug 8, 2023 |
| CVE-2023-35391 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | HIGH | 7.5 | Aug 8, 2023 |
| CVE-2021-43877 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | HIGH | 8.8 | Dec 15, 2021 |
| CVE-2021-34532 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability | MEDIUM | 5.5 | Aug 12, 2021 |
| CVE-2021-1723 | ASP.NET Core and Visual Studio Denial of Service Vulnerability | HIGH | 7.5 | Jan 12, 2021 |
| CVE-2020-1045 | Microsoft ASP.NET Core Security Feature Bypass Vulnerability | HIGH | 7.5 | Sep 11, 2020 |
| CVE-2020-1597 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | Aug 17, 2020 |
| CVE-2020-1161 | ASP.NET Core Denial of Service Vulnerability | HIGH | 7.5 | May 21, 2020 |
| CVE-2020-0603 | dotnet: Memory Corruption in SignalR | HIGH | 8.8 | Jan 14, 2020 |
| CVE-2020-0602 | dotnet: Denial of service via backpressure issue | HIGH | 7.5 | Jan 14, 2020 |
| CVE-2019-1302 | An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web… | HIGH | 8.8 | Sep 11, 2019 |
| CVE-2019-1075 | A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. | MEDIUM | 6.1 | Jul 15, 2019 |
| CVE-2019-0982 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | HIGH | 7.5 | May 16, 2019 |
| CVE-2019-0815 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | HIGH | 7.5 | Apr 9, 2019 |
Showing 1 to 25 of 39 CVEs