cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-35391,https://securityvulnerability.io/vulnerability/CVE-2023-35391,ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability,ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability,Microsoft,"Microsoft Visual Studio 2022 Version 17.2,Microsoft Visual Studio 2022 Version 17.4,Microsoft Visual Studio 2022 Version 17.6,Asp.net Core 2.1,.net 6.0,.net 7.0",6.2,MEDIUM,0.003539999946951866,false,false,false,false,,false,false,2023-08-08T19:15:00.000Z,0 CVE-2023-38180,https://securityvulnerability.io/vulnerability/CVE-2023-38180,.NET and Visual Studio Denial of Service Vulnerability,.NET and Visual Studio Denial of Service Vulnerability,Microsoft,"Asp.net Core 2.1,.net 6.0,.net 7.0,Microsoft Visual Studio 2022 Version 17.2,Microsoft Visual Studio 2022 Version 17.4,Microsoft Visual Studio 2022 Version 17.6",7.5,HIGH,0.006639999803155661,true,false,false,true,,false,false,2023-08-08T19:15:00.000Z,0 CVE-2021-34532,https://securityvulnerability.io/vulnerability/CVE-2021-34532,ASP.NET Core and Visual Studio Information Disclosure Vulnerability,ASP.NET Core and Visual Studio Information Disclosure Vulnerability,Microsoft,"Asp.net Core 2.1,Asp.net Core 3.1,Asp.net Core 5.0,Microsoft Visual Studio 2019 Version 16.4 (includes 16.0 - 16.3),Microsoft Visual Studio 2019 Version 16.7 (includes 16.0 – 16.6),Microsoft Visual Studio 2019 Version 16.9 (includes 16.0 - 16.8),Microsoft Visual Studio 2019 Version 16.10 (includes 16.0 - 16.9),Visual Studio 2019 For Mac Version 8.10",5.5,MEDIUM,0.0006099999882280827,false,false,false,false,,false,false,2021-08-12T18:12:05.000Z,0 CVE-2020-1045,https://securityvulnerability.io/vulnerability/CVE-2020-1045,Microsoft ASP.NET Core Security Feature Bypass Vulnerability,"
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.
The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.
The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.
",Microsoft,"Asp.net Core 2.1,Asp.net Core 3.1",7.5,HIGH,0.0013699999544769526,false,false,false,false,,false,false,2020-09-11T00:00:00.000Z,0 CVE-2020-1597,https://securityvulnerability.io/vulnerability/CVE-2020-1597,ASP.NET Core Denial of Service Vulnerability,"A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests. ",Microsoft,"Asp.net Core 2.1,Asp.net Core 3.1,Microsoft Visual Studio 2019 Version 16.4 (includes 16.0 - 16.3),Microsoft Visual Studio 2017 Version 15.9 (includes 15.0 - 15.8),Microsoft Visual Studio 2019 Version 16.0,Microsoft Visual Studio 2019 Version 16.7 (includes 16.0 – 16.6)",7.5,HIGH,0.028669999912381172,false,false,false,false,,false,false,2020-08-17T19:15:00.000Z,0