Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mono

First CVE: Mar 14, 2005Active for: 21 yearsTotal CVEs: 31
32.0
VTI Score
Medium

Mono is a cross-platform runtime framework and associated tools that enable execution of .NET applications on non-Windows environments, with a footprint spanning the core runtime, web server components like XSP, graphics libraries such as libgdiplus, and related middleware. The vendor's vulnerability surface clusters around input-handling and web-layer weaknesses—including cross-site scripting, improper input validation, and information-disclosure flaws—characteristic of interpreters and web frameworks that parse untrusted application code and HTTP traffic. While the vendor's disclosures do not skew toward critical severity, public exploit code has an elevated tendency to emerge for identified flaws, reflecting the accessible nature of web and runtime attack vectors. Defenders deploying Mono should prioritize patches for web-facing components and validate input handling in hosted applications; current severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 96% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mono over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2005
21 years ago
Most Recent CVE
Feb 22, 2023
1,248 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4254HIGH
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic con
Dec 6, 20107.542NOYES
CVE-2015-2320CRITICAL
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
Jan 8, 20189.831NONO
CVE-2008-3906MEDIUM
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequen
Sep 4, 20084.329NOYES
CVE-2023-26314HIGH
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono
Feb 22, 20238.827NONO
CVE-2020-12471CRITICAL
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5U
Apr 29, 20209.825NONO
CVE-2012-3543HIGH
mono 2.10.x ASP.NET Web Form Hash collision DoS
Nov 21, 20197.524NONO
CVE-2006-6104MEDIUM
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by append
Dec 21, 20065.024NOYES
CVE-2019-0757MEDIUM
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet
Apr 9, 20196.523NONO
CVE-2015-2319HIGH
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" i
Jan 8, 20187.523NONO
CVE-2015-2318HIGH
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake stat
Jan 8, 20188.123NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
66%
28%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (34.5%)
Unknown19 (65.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (31.0%)
High1 (3.4%)
Unknown19 (65.5%)
User Interaction
None8 (27.6%)
Unknown19 (65.5%)
Required2 (6.9%)
Privileges Required
Low2 (6.9%)
High2 (6.9%)
None6 (20.7%)
Unknown19 (65.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
10.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mono.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mono — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mono's Products

View all 4 CNAs →

Top CWEs