Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mono Project

First CVE: Mar 14, 2005Active for: 21 yearsTotal CVEs: 31

Mono Project maintains a cross-platform implementation of the .NET framework widely used in server and desktop applications, though its vulnerability footprint remains modestly represented relative to its deployment scope. The recurring exposure concentrates in the core Mono runtime and graphics library (libgdiplus) and clusters around input-handling weaknesses including improper validation and cross-site scripting, typical of runtime interpreters and graphics-processing components that parse untrusted data. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 92% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mono Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2005
21 years ago
Most Recent CVE
Feb 22, 2023
1,249 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4254HIGH
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic con
Dec 6, 20107.542NOYES
CVE-2015-2320CRITICAL
The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.
Jan 8, 20189.831NONO
CVE-2008-3906MEDIUM
CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequen
Sep 4, 20084.329NOYES
CVE-2023-26314HIGH
The mono package before 6.8.0.105+dfsg-3.3 for Debian allows arbitrary code execution because the application/x-ms-dos-executable MIME type is associated with an un-sandboxed Mono
Feb 22, 20238.827NONO
CVE-2020-12471CRITICAL
MonoX through 5.1.40.5152 allows remote code execution via HTML5Upload.ashx or Pages/SocialNetworking/lng/en-US/PhotoGallery.aspx because of deserialization in ModuleGallery.HTML5U
Apr 29, 20209.825NONO
CVE-2012-3543HIGH
mono 2.10.x ASP.NET Web Form Hash collision DoS
Nov 21, 20197.524NONO
CVE-2006-6104MEDIUM
The System.Web class in the XSP for ASP.NET server 1.1 through 2.0 in Mono does not properly verify local pathnames, which allows remote attackers to (1) read source code by append
Dec 21, 20065.024NOYES
CVE-2019-0757MEDIUM
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet
Apr 9, 20196.523NONO
CVE-2015-2319HIGH
The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" i
Jan 8, 20187.523NONO
CVE-2015-2318HIGH
The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake stat
Jan 8, 20188.123NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
66%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (34.5%)
Unknown19 (65.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (31.0%)
High1 (3.4%)
Unknown19 (65.5%)
User Interaction
None8 (27.6%)
Unknown19 (65.5%)
Required2 (6.9%)
Privileges Required
Low2 (6.9%)
High2 (6.9%)
None6 (20.7%)
Unknown19 (65.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
10.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mono Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mono Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mono Project's Products

View all 4 CNAs →

Top CWEs