threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft asp.net core
Product
microsoft asp.net core
40 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2026-40372
>= 10.0.0 and < 10.0.7
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a netw
9.1
CRITICAL
CVE-2026-26130
>= 8.0.0 and < 8.0.25
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a networ
7.5
HIGH
CVE-2025-55315
>= 2.3.0 and < 2.3.6
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to
9.9
CRITICAL
CVE-2025-26682
>= 8.0.0 and < 8.0.15
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a networ
7.5
HIGH
CVE-2025-24070
>= 8.0.0 and < 8.0.14
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
7.0
HIGH
CVE-2024-21404
>= 6.0.0 and < 6.0.27
.NET Denial of Service Vulnerability
7.5
HIGH
CVE-2024-21386
>= 6.0.0 and < 6.0.27
.NET Denial of Service Vulnerability
7.5
HIGH
CVE-2023-36558
>= 6.0.0 and < 6.0.25
ASP.NET Core Security Feature Bypass Vulnerability
6.2
MEDIUM
CVE-2023-36038
all versions
ASP.NET Core Denial of Service Vulnerability
8.2
HIGH
CVE-2023-44487
>= 6.0.0 and < 6.0.23
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5
HIGH
CVE-2023-38180
>= 2.1 and < 2.1.40
.NET and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2023-35391
>= 2.1 and < 2.1.40
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
6.2
MEDIUM
CVE-2021-43877
all versions
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-34532
>= 2.1 and <= 2.1.2
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2021-1723
>= 3.1 and <= 3.1.10
ASP.NET Core and Visual Studio Denial of Service Vulnerability
7.5
HIGH
CVE-2020-1045
>= 2.1 and <= 2.1.21
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NE
7.5
HIGH
CVE-2020-1597
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited
7.5
HIGH
CVE-2020-1161
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2020-0603
all versions
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attac
8.8
HIGH
CVE-2020-0602
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2019-1302
all versions
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fa
8.8
HIGH
CVE-2019-1075
all versions
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
6.1
MEDIUM
CVE-2019-0982
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2019-0815
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2019-0564
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2019-0548
all versions
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vu
7.5
HIGH
CVE-2018-8416
all versions
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability
6.5
MEDIUM
CVE-2018-8292
all versions
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect
7.5
HIGH
CVE-2018-8409
>= 2.1 and < 2.1.4
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of
7.5
HIGH
CVE-2018-8356
all versions
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, ak
5.5
MEDIUM
CVE-2018-8171
all versions
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.N
7.5
HIGH
CVE-2018-0875
all versions
.NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially
7.5
HIGH
CVE-2018-0808
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how ASP.NET web applications handle web reques
7.5
HIGH
CVE-2018-0787
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from tem
8.8
HIGH
CVE-2018-0785
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "AS
6.5
MEDIUM
CVE-2018-0784
all versions
ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.N
8.8
HIGH
CVE-2017-8700
all versions
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normal
7.5
HIGH
CVE-2017-11883
all versions
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web
7.5
HIGH
CVE-2017-11879
all versions
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially c
8.8
HIGH
CVE-2017-11770
all versions
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin