Microsoft Asp.Net Core vulnerabilities
36 known vulnerabilities affecting microsoft/asp.net_core.
Total CVEs
36
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH28MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2019-0548P3HIGHCVSS 7.5v2.1v2.22019-01-08
CVE-2019-0548 [HIGH] CWE-19 CVE-2019-0548: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564.
nvd
CVE-2025-24070P3HIGHCVSS 7.0≥ 8.0.0, < 8.0.14≥ 9.0.0, < 9.0.32025-03-11
CVE-2025-24070 [HIGH] CWE-1390 CVE-2025-24070: Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate p
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2023-35391P3HIGHCVSS 7.5≥ 2.1, < 2.1.402023-08-08
CVE-2023-35391 [HIGH] CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2020-0602P3HIGHCVSS 7.5v2.1v3.0+1 more2020-01-14
CVE-2020-0602 [HIGH] CVE-2020-0602: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
nvd
CVE-2019-0815P3HIGHCVSS 7.5v2.22019-04-09
CVE-2019-0815 [HIGH] CWE-19 CVE-2019-0815: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
nvd
CVE-2019-0982P3HIGHCVSS 7.5v2.1v2.22019-05-16
CVE-2019-0982 [HIGH] CWE-19 CVE-2019-0982: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
nvd
CVE-2018-8416P3MEDIUMCVSS 6.5v2.12018-11-14
CVE-2018-8416 [MEDIUM] CVE-2018-8416: A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NE
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.
nvd
CVE-2021-43877P3HIGHCVSS 7.8v3.1v5.0+1 more2021-12-15
CVE-2021-43877 [HIGH] CVE-2021-43877: ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2020-1161P3HIGHCVSS 7.5v3.12020-05-21
CVE-2020-1161 [HIGH] CVE-2020-1161: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
nvd
CVE-2018-8409P3HIGHCVSS 7.5≥ 2.1, < 2.1.4v2.12018-09-13
CVE-2018-8409 [HIGH] CVE-2018-8409: A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
nvd
CVE-2021-1723P3HIGHCVSS 7.5≥ 3.1, ≤ 3.1.10≥ 5.0, ≤ 5.0.12021-01-12
CVE-2021-1723 [HIGH] CVE-2021-1723: ASP.NET Core and Visual Studio Denial of Service Vulnerability
ASP.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2018-0785P4MEDIUMCVSS 6.5v2.02018-01-10
CVE-2018-0785 [MEDIUM] CWE-352 CVE-2018-0785: ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET C
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
nvd
CVE-2023-36558P4MEDIUMCVSS 5.5≥ 6.0.0, < 6.0.25≥ 7.0.0, < 7.0.14+1 more2023-11-14
CVE-2023-36558 [MEDIUM] CVE-2023-36558: ASP.NET Core Security Feature Bypass Vulnerability
ASP.NET Core Security Feature Bypass Vulnerability
nvd
CVE-2019-1075P4MEDIUMCVSS 6.1v2.1v2.22019-07-15
CVE-2019-1075 [MEDIUM] CWE-601 CVE-2019-1075: A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Co
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
nvd
CVE-2018-8356P4MEDIUMCVSS 5.5v1.0v1.1+1 more2018-07-11
CVE-2018-8356 [MEDIUM] CWE-295 CVE-2018-8356: A security feature bypass vulnerability exists when Microsoft .NET Framework components do not corre
A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, ASP.NET Core 1.1, Microsoft .NET Framework 4.5.2, AS
nvd
CVE-2021-34532P4MEDIUMCVSS 5.5≥ 2.1, ≤ 2.1.2≥ 3.1, ≤ 3.1.17+1 more2021-08-12
CVE-2021-34532 [MEDIUM] CVE-2021-34532: ASP.NET Core and Visual Studio Information Disclosure Vulnerability
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
nvd
← Previous2 / 2