All apps
A
ASP.NET Core Runtime
RuntimeASP.NET Core runtime for hosting web applications and APIs
Latest versions
Stable
macOSWindowsLinux
10.0.1111 Aug 2026Current
WindowsmacOSLinux
9.0.1911 Aug 2026Enterprise Stable
WindowsmacOSLinux
8.0.3011 Aug 2026Actively exploited
0
CISA KEV · 2 lifetime
Affecting latest
0
v8.0.30
Known CVEs
39
across all versions, as matched by PemSync
Last checked
6 Sep 2026, 0:15
The latest tracked version (8.0.30) is not affected by any matched vulnerability — all 39 recorded CVEs are fixed in versions you're past.
| CVE | Severity | EPSS pct | Status | Score source | |
|---|---|---|---|---|---|
CVE-2023-44487Exploited | HIGH 7.5 | 100% | Latest not affected | NVD | 10 Oct 2023 |
CVE-2023-38180Exploited | HIGH 7.5 | 96% | Latest not affected | NVD | 8 Aug 2023 |
| HIGHvendor | 83% | Latest not affected | — | 9 Jun 2026 | |
| — | 96% | Latest not affected | — | 21 Apr 2026 | |
| — | 86% | Latest not affected | — | 10 Mar 2026 | |
| — | 99% | Latest not affected | — | 14 Oct 2025 | |
| — | 75% | Latest not affected | — | 8 Apr 2025 | |
| — | 60% | Latest not affected | — | 11 Mar 2025 | |
| — | 85% | Latest not affected | — | 13 Feb 2024 | |
| — | 83% | Latest not affected | — | 13 Feb 2024 | |
| — | 63% | Latest not affected | — | 14 Nov 2023 | |
| — | 85% | Latest not affected | — | 14 Nov 2023 | |
| — | 78% | Latest not affected | — | 8 Aug 2023 | |
| — | 51% | Latest not affected | — | 15 Dec 2021 | |
| — | 66% | Latest not affected | — | 12 Aug 2021 | |
| — | 92% | Latest not affected | — | 12 Jan 2021 | |
| — | 93% | Latest not affected | — | 11 Sep 2020 | |
| — | 93% | Latest not affected | — | 17 Aug 2020 | |
| — | 92% | Latest not affected | — | 21 May 2020 | |
| — | 97% | Latest not affected | — | 14 Jan 2020 | |
| — | 94% | Latest not affected | — | 14 Jan 2020 | |
| — | 91% | Latest not affected | — | 11 Sep 2019 | |
| — | 85% | Latest not affected | — | 15 Jul 2019 | |
| — | 93% | Latest not affected | — | 16 May 2019 | |
| — | 94% | Latest not affected | — | 9 Apr 2019 |
Showing 1–25 of 39
Page 1 of 2
PemSync reports known, cataloged exploited vulnerabilities (CISA KEV) and published CVEs. It is not a zero-day detection or threat-intelligence system — a vulnerability may be exploited before it appears here. Absence of data does not mean an app is secure.