← Back

Asp.net Core

asp.net_core

Vendor: Microsoft • 39 CVEs

CVEs (39)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3.net
Asp.net CoreVisual Studio 2026
Jul 15, 2026
Jun 9, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
1Microsoft
1Asp.net Core
Jul 15, 2026
Apr 21, 2026
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
1Asp.net Core
Jul 15, 2026
Mar 10, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
1Microsoft
2Asp.net Core
Visual Studio 2022
Jun 17, 2026
Oct 14, 2025
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
1Microsoft
2Asp.net Core
Visual Studio 2022
Jun 17, 2026
Apr 8, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
1Microsoft
2Asp.net Core
Visual Studio 2022
Jun 17, 2026
Mar 11, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
1Microsoft
2Asp.net Core
Visual Studio 2022
Jun 17, 2026
Feb 13, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
.NET Denial of Service Vulnerability
1Microsoft
2Asp.net Core
Visual Studio 2022
Jun 17, 2026
Feb 13, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
.NET Denial of Service Vulnerability
1Microsoft
3.net
Asp.net CoreVisual Studio 2022
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
ASP.NET Core Security Feature Bypass Vulnerability
1Microsoft
2Asp.net Core
Visual Studio 2022
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ASP.NET Core Denial of Service Vulnerability
33Akka
AmazonApache+30 more
165.net
3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 more
Jun 17, 2026
Oct 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
2Fedoraproject
Microsoft
4.net
Asp.net CoreFedora+1 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
.NET and Visual Studio Denial of Service Vulnerability
1Microsoft
3.net
Asp.net CoreVisual Studio 2022
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
1Microsoft
3Asp.net Core
Visual Studio 2019Visual Studio 2022
Jun 17, 2026
Dec 15, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
1Microsoft
2Asp.net Core
Visual Studio 2019
Jun 17, 2026
Aug 12, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
2Fedoraproject
Microsoft
3Asp.net Core
FedoraVisual Studio 2019
Jun 17, 2026
Jan 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ASP.NET Core and Visual Studio Denial of Service Vulnerability
3Fedoraproject
MicrosoftRedhat
6Asp.net Core
Enterprise LinuxEnterprise Linux Aus+3 more
Jun 17, 2026
Sep 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker...Show more
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>Show less
2Fedoraproject
Microsoft
4Asp.net Core
FedoraVisual Studio 2017+1 more
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web applicatio...Show more
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.Show less
1Microsoft
3Asp.net Core
Visual Studio 2017Visual Studio 2019
Jun 17, 2026
May 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
2Microsoft
Redhat
3Asp.net Core
Enterprise LinuxEnterprise Linux Eus
Jun 17, 2026
Jan 14, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context o...Show more
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'.Show less