Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
asp.net vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2005-0452
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote malicious users to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, includi...
Microsoft Asp.net 1.0
Microsoft Asp.net 1.1
1 EDB exploit
1 Github repository
NA
CVE-2014-4075
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 up to and including 5.1 allows remote malicious users to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."
Microsoft Asp.net Model View Controller 5.0
Microsoft Asp.net Model View Controller 5.1
Microsoft Asp.net Model View Controller 3.0
Microsoft Asp.net Model View Controller 4.0
Microsoft Asp.net Model View Controller 2.0
6.1
CVSSv3
CVE-2019-1075
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
Microsoft Asp.net Core 2.2
Microsoft Asp.net Core 2.1
1 Article
7.5
CVSSv3
CVE-2019-0982
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Microsoft Asp.net Core 2.1
Microsoft Asp.net Core 2.2
1 Article
9.8
CVSSv3
CVE-2017-11317
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote malicious users to perform arbitrary file uploads or execute arbitrary code.
Telerik Ui For Asp.net Ajax 2017.2.503
Telerik Ui For Asp.net Ajax 2017.2.621
Telerik Ui For Asp.net Ajax
1 EDB exploit
7 Github repositories
8.8
CVSSv3
CVE-2020-0603
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execu...
Microsoft Asp.net Core 2.1
Microsoft Asp.net Core 3.0
Microsoft Asp.net Core 3.1
Redhat Enterprise Linux 8.0
Redhat Enterprise Linux Eus 8.1
2 Articles
7.5
CVSSv3
CVE-2020-0602
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Microsoft Asp.net Core 2.1
Microsoft Asp.net Core 3.0
Microsoft Asp.net Core 3.1
Redhat Enterprise Linux 8.0
Redhat Enterprise Linux Eus 8.1
1 Article
NA
CVE-2014-4958
Cross-site scripting (XSS) vulnerability in Telerik UI for ASP.NET AJAX RadEditor control 2014.1.403.35, 2009.3.1208.20, and other versions allows remote malicious users to inject arbitrary web script or HTML via CSS expressions in style attributes.
Telerik Asp.net Ajax Radeditor Control 2009.3.1208.20
Telerik Asp.net Ajax Radeditor Control
1 Article
NA
CVE-2005-2224
aspnet_wp.exe in Microsoft ASP.NET web services allows remote malicious users to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.
Microsoft Asp.net -
NA
CVE-2003-0768
Microsoft ASP.Net 1.1 allows remote malicious users to bypass the Cross-Site Scripting (XSS) and Script Injection protection feature via a null character in the beginning of a tag name.
Microsoft Asp.net 1.1
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2006-4304
CVE-2024-4240
arbitrary
CVE-2024-31601
XSS
CVE-2023-20198
CVE-2024-4256
CVE-2024-3342
encryption
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »