← Back

Asp.net Model View Controller

asp.net_model_view_controller

Vendor: Microsoft • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
3Asp.net Core
Asp.net Model View ControllerAsp.net Webpages
Jun 17, 2026
Jul 11, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET...Show more
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.Show less
1Microsoft
18Asp.net Model View Controller
Microsoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorer+15 more
May 13, 2026
May 12, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
1Microsoft
18Asp.net Model View Controller
Microsoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorer+15 more
May 13, 2026
May 12, 2017
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
1Microsoft
18Asp.net Model View Controller
Microsoft.aspnetcore.mvc.abstractionsMicrosoft.aspnetcore.mvc.apiexplorer+15 more
May 13, 2026
May 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function i...Show more
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.Show less
1Microsoft
1Asp.net Model View Controller
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "...Show more
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."Show less