VYPR

Asp.net Core

Sign in to watch

by Microsoft

CVEs (9)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-40372Cri0.599.10.00Apr 21, 2026Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2017-11879Hig0.588.80.10Nov 15, 2017ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
CVE-2026-26130Hig0.497.50.03Mar 10, 2026Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2017-8700Hig0.497.50.07Nov 15, 2017ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".
CVE-2020-10450.020.20Sep 11, 2020<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>
CVE-2020-15970.010.08Aug 17, 2020A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
CVE-2021-438770.000.01Dec 15, 2021ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-345320.000.00Aug 12, 2021ASP.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-17230.000.04Jan 12, 2021ASP.NET Core and Visual Studio Denial of Service Vulnerability