VYPR

Aspnetcore

by Microsoft

Source repositories

CVEs (52)

  • CVE-2020-1147HigKEVJul 14, 2020
    risk 0.73cvss 7.8epss 0.94

    A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

  • CVE-2025-55315CriOct 14, 2025
    risk 0.66cvss 9.9epss 0.66

    Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-38180HigKEVAug 8, 2023
    risk 0.62cvss 7.5epss 0.15

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2026-40372CriApr 21, 2026
    risk 0.60cvss 9.1epss 0.11

    Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2020-0606HigJan 14, 2020
    risk 0.59cvss 8.8epss 0.16

    A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code…

  • CVE-2020-0605HigJan 14, 2020
    risk 0.59cvss 8.8epss 0.17

    A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code…

  • CVE-2020-0603HigJan 14, 2020
    risk 0.59cvss 8.8epss 0.20

    A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution…

  • CVE-2019-1302HigSep 11, 2019
    risk 0.58cvss 8.8epss 0.05

    An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.

  • CVE-2018-0787HigMar 14, 2018
    risk 0.58cvss 8.8epss 0.10

    ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".

  • CVE-2018-0784HigJan 10, 2018
    risk 0.58cvss 8.8epss 0.07

    ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.

  • CVE-2017-11879HigNov 15, 2017
    risk 0.58cvss 8.8epss 0.09

    ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".

  • CVE-2021-43877HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.01

    ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2023-36038HigNov 14, 2023
    risk 0.54cvss 8.2epss 0.03

    ASP.NET Core Denial of Service Vulnerability

  • CVE-2020-1108HigMay 21, 2020
    risk 0.50cvss 7.5epss 0.12

    A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

  • CVE-2019-0545HigJan 8, 2019
    risk 0.50cvss 7.5epss 0.10

    An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET…

  • CVE-2018-8292HigOct 10, 2018
    risk 0.50cvss 7.5epss 0.15

    An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

  • CVE-2018-8171HigJul 11, 2018
    risk 0.50cvss 7.5epss 0.10

    A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.

  • CVE-2018-0875HigMar 14, 2018
    risk 0.50cvss 7.5epss 0.09

    .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".

  • CVE-2017-8700HigNov 15, 2017
    risk 0.50cvss 7.5epss 0.10

    ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".

Page 1 of 3