cbcvebase.

Microsoft Microsoft.Aspnetcore.Identity vulnerabilities

5 known vulnerabilities affecting microsoft/microsoft.aspnetcore.identity.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5

Vulnerabilities

Page 1 of 1
CVE-2024-38229P3HIGHCVSS 8.1≥ >=6.0.0, ≤ 6.0.362024-10-08
CVE-2024-38229 [HIGH] CWE-416 CVE-2024-38229: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-33170P3HIGHCVSS 8.1≥ 0, < 2.1.392023-07-11
CVE-2023-33170 [HIGH] CWE-362 Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability # Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 2.1 and above. This advisory also provides guidance on what developers can d
ghsaosv
CVE-2018-8171P3HIGH≥ 1.0.0, < 1.0.6≥ 1.1.0, < 1.1.6+2 more2018-10-16
CVE-2018-8171 [HIGH] CWE-287 Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated Security feature bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.N
ghsaosv
CVE-2025-24070P3HIGHCVSS 7.0≥ 2.3.0, < 2.3.12025-03-11
CVE-2025-24070 [HIGH] CWE-1390 Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability # Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core 9.0, ASP.NET Core 8.0, ASP.NET Core 6.0, and ASP.NET Core 2.3. This advisory a
ghsaosv
CVE-2025-7326P3HIGHCVSS 7.0≥ >=6.0.0, ≤ 6.0.362025-07-08
CVE-2025-7326 [HIGH] CWE-1390 CVE-2025-7326: Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry.
nvd
Microsoft Microsoft.Aspnetcore.Identity vulnerabilities | cvebase