« Volver al listado

Microsoft

Microsoft Asp.net Core: vulnerabilidades y CVE

Microsoft Asp.net Core tiene 44 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE44
Últimos 12 meses6
Críticas2
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-38180Alta (7.5)14%⚠ Explotación activa8 ago 2023
.NET and Visual Studio Denial of Service Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-69304Media (5.9)0.88%—8 sept 2026
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-57099Alta (7.5)1.2%—8 sept 2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-45591Alta (7.5)2.4%—9 jun 2026
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-40372Crítica (9.1)0.82%—21 abr 2026
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-26130Alta (7.5)2.4%—10 mar 2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2025-55315Crítica (9.9)66%—14 oct 2025
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
CVE-2025-7326Alta (7)0.65%—8 jul 2025
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there…
CVE-2025-32016Media (4.7)0.10%—9 abr 2025
Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly Azure AD v2.0 endpoint) and AAD B2C. This…
CVE-2025-26682Alta (7.5)1.7%—8 abr 2025
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2025-24070Alta (7)0.98%—11 mar 2025
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2024-39694Media (4.7)0.53%—31 jul 2024
Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain functions in IdentityServer will incorrectly treat as local and…
CVE-2024-21404Alta (7.5)2.7%—13 feb 2024
.NET Denial of Service Vulnerability
CVE-2024-21386Alta (7.5)2.4%—13 feb 2024
.NET Denial of Service Vulnerability
CVE-2023-36558Media (5.5)1.1%—14 nov 2023
ASP.NET Core Security Feature Bypass Vulnerability
CVE-2023-36038Alta (7.5)2.8%—14 nov 2023
ASP.NET Core Denial of Service Vulnerability
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-38180Alta (7.5)14%⚠ Explotación activa8 ago 2023
.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-35391Alta (7.5)1.9%—8 ago 2023
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
CVE-2021-43877Alta (7.8)0.72%—15 dic 2021
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
CVE-2021-34532Media (5.5)1.2%—12 ago 2021
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-1723Alta (7.5)4.9%—12 ene 2021
ASP.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2020-1045Alta (7.5)5.9%—11 sept 2020
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker…
CVE-2020-1597Alta (7.5)6.6%—17 ago 2020
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web…
CVE-2020-1161Alta (7.5)5.1%—21 may 2020
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web…
CVE-2020-0603Alta (8.8)21%—14 ene 2020
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context…
CVE-2020-0602Alta (7.5)7.6%—14 ene 2020
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
CVE-2019-1302Alta (8.8)4.8%—11 sept 2019
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege…
CVE-2019-1075Media (6.1)2.6%—15 jul 2019
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
CVE-2019-0982Alta (7.5)6.7%—16 may 2019
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
CVE-2019-0815Alta (7.5)7.0%—9 abr 2019
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1499.004 Application or System Exploitation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft