VYPR

Aspnetcore

by Microsoft

Source repositories

CVEs (58)

  • CVE-2017-11883HigNov 15, 2017
    risk 0.49cvss 7.5epss 0.09

    .NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".

  • CVE-2017-11770HigNov 15, 2017
    risk 0.49cvss 7.5epss 0.05

    .NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate…

  • CVE-2025-7326HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.01

    Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon…

  • CVE-2025-24070HigMar 11, 2025
    risk 0.46cvss 7.0epss 0.01

    Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2018-8416MedNov 14, 2018
    risk 0.43cvss 6.5epss 0.07

    A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.

  • CVE-2026-45591HigJun 9, 2026
    risk 0.42cvss 7.5epss 0.02

    Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-42899HigMay 12, 2026
    risk 0.42cvss 7.5epss 0.02

    Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2018-8409HigSep 13, 2018
    risk 0.42cvss 7.5epss 0.07

    A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

  • CVE-2018-0785MedJan 10, 2018
    risk 0.42cvss 6.5epss 0.03

    ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".

  • CVE-2023-36558MedNov 14, 2023
    risk 0.40cvss 6.2epss 0.01

    ASP.NET Core Security Feature Bypass Vulnerability

  • CVE-2023-35391MedAug 8, 2023
    risk 0.40cvss 6.2epss 0.02

    ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

  • CVE-2019-1075MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.03

    A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

  • CVE-2019-0657MedMar 5, 2019
    risk 0.39cvss 5.9epss 0.05

    A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

  • CVE-2026-69304MedSep 8, 2026
    risk 0.38cvss 5.9epss 0.01

    Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2018-8356MedJul 11, 2018
    risk 0.36cvss 5.5epss 0.01

    A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework…

  • CVE-2021-34532MedAug 12, 2021
    risk 0.29cvss 5.5epss 0.01

    ASP.NET Core and Visual Studio Information Disclosure Vulnerability

  • CVE-2026-50506HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-45646HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Page 3 of 3