Microsoft
Microsoft Asp.net Core: vulnerabilidades y CVE
Microsoft Asp.net Core tiene 44 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses6
Críticas2
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-38180 | Alta (7.5) | 14% | ⚠ Explotación activa | 8 ago 2023 | .NET and Visual Studio Denial of Service Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69304 | Media (5.9) | 0.88% | — | 8 sept 2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2026-57099 | Alta (7.5) | 1.2% | — | 8 sept 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2026-45591 | Alta (7.5) | 2.4% | — | 9 jun 2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2026-40372 | Crítica (9.1) | 0.82% | — | 21 abr 2026 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-26130 | Alta (7.5) | 2.4% | — | 10 mar 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2025-55315 | Crítica (9.9) | 66% | — | 14 oct 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. |
| CVE-2025-7326 | Alta (7) | 0.65% | — | 8 jul 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there… |
| CVE-2025-32016 | Media (4.7) | 0.10% | — | 9 abr 2025 | Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This… |
| CVE-2025-26682 | Alta (7.5) | 1.7% | — | 8 abr 2025 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2025-24070 | Alta (7) | 0.98% | — | 11 mar 2025 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2024-39694 | Media (4.7) | 0.53% | — | 31 jul 2024 | Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and… |
| CVE-2024-21404 | Alta (7.5) | 2.7% | — | 13 feb 2024 | .NET Denial of Service Vulnerability |
| CVE-2024-21386 | Alta (7.5) | 2.4% | — | 13 feb 2024 | .NET Denial of Service Vulnerability |
| CVE-2023-36558 | Media (5.5) | 1.1% | — | 14 nov 2023 | ASP.NET Core Security Feature Bypass Vulnerability |
| CVE-2023-36038 | Alta (7.5) | 2.8% | — | 14 nov 2023 | ASP.NET Core Denial of Service Vulnerability |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-38180 | Alta (7.5) | 14% | ⚠ Explotación activa | 8 ago 2023 | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2023-35391 | Alta (7.5) | 1.9% | — | 8 ago 2023 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability |
| CVE-2021-43877 | Alta (7.8) | 0.72% | — | 15 dic 2021 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability |
| CVE-2021-34532 | Media (5.5) | 1.2% | — | 12 ago 2021 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability |
| CVE-2021-1723 | Alta (7.5) | 4.9% | — | 12 ene 2021 | ASP.NET Core and Visual Studio Denial of Service Vulnerability |
| CVE-2020-1045 | Alta (7.5) | 5.9% | — | 11 sept 2020 | <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker… |
| CVE-2020-1597 | Alta (7.5) | 6.6% | — | 17 ago 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web… |
| CVE-2020-1161 | Alta (7.5) | 5.1% | — | 21 may 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web… |
| CVE-2020-0603 | Alta (8.8) | 21% | — | 14 ene 2020 | A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context… |
| CVE-2020-0602 | Alta (7.5) | 7.6% | — | 14 ene 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. |
| CVE-2019-1302 | Alta (8.8) | 4.8% | — | 11 sept 2019 | An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege… |
| CVE-2019-1075 | Media (6.1) | 2.6% | — | 15 jul 2019 | A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. |
| CVE-2019-0982 | Alta (7.5) | 6.7% | — | 16 may 2019 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. |
| CVE-2019-0815 | Alta (7.5) | 7.0% | — | 9 abr 2019 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.