Home/Product/microsoft asp.net core
Product

microsoft asp.net core

40 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-40372
>= 10.0.0 and < 10.0.7
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a netw
9.1CRITICAL
CVE-2026-26130
>= 8.0.0 and < 8.0.25
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a networ
7.5HIGH
CVE-2025-55315
>= 2.3.0 and < 2.3.6
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to
9.9CRITICAL
CVE-2025-26682
>= 8.0.0 and < 8.0.15
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a networ
7.5HIGH
CVE-2025-24070
>= 8.0.0 and < 8.0.14
Weak authentication in ASP.NET Core &amp; Visual Studio allows an unauthorized attacker to elevate privileges over a network.
7.0HIGH
CVE-2024-21404
>= 6.0.0 and < 6.0.27
.NET Denial of Service Vulnerability
7.5HIGH
CVE-2024-21386
>= 6.0.0 and < 6.0.27
.NET Denial of Service Vulnerability
7.5HIGH
CVE-2023-36558
>= 6.0.0 and < 6.0.25
ASP.NET Core Security Feature Bypass Vulnerability
6.2MEDIUM
CVE-2023-36038
all versions
ASP.NET Core Denial of Service Vulnerability
8.2HIGH
CVE-2023-44487
>= 6.0.0 and < 6.0.23
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5HIGH
CVE-2023-38180
>= 2.1 and < 2.1.40
.NET and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2023-35391
>= 2.1 and < 2.1.40
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
6.2MEDIUM
CVE-2021-43877
all versions
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
8.8HIGH
CVE-2021-34532
>= 2.1 and <= 2.1.2
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
5.5MEDIUM
CVE-2021-1723
>= 3.1 and <= 3.1.10
ASP.NET Core and Visual Studio Denial of Service Vulnerability
7.5HIGH
CVE-2020-1045
>= 2.1 and <= 2.1.21
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NE
7.5HIGH
CVE-2020-1597
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited
7.5HIGH
CVE-2020-1161
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2020-0603
all versions
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attac
8.8HIGH
CVE-2020-0602
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2019-1302
all versions
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fa
8.8HIGH
CVE-2019-1075
all versions
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
6.1MEDIUM
CVE-2019-0982
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2019-0815
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2019-0564
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2019-0548
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vu
7.5HIGH
CVE-2018-8416
all versions
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability
6.5MEDIUM
CVE-2018-8292
all versions
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect
7.5HIGH
CVE-2018-8409
>= 2.1 and < 2.1.4
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of
7.5HIGH
CVE-2018-8356
all versions
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, ak
5.5MEDIUM
CVE-2018-8171
all versions
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.N
7.5HIGH
CVE-2018-0875
all versions
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially
7.5HIGH
CVE-2018-0808
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web reques
7.5HIGH
CVE-2018-0787
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from tem
8.8HIGH
CVE-2018-0785
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "AS
6.5MEDIUM
CVE-2018-0784
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.N
8.8HIGH
CVE-2017-8700
all versions
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normal
7.5HIGH
CVE-2017-11883
all versions
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web
7.5HIGH
CVE-2017-11879
all versions
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially c
8.8HIGH
CVE-2017-11770
all versions
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin