MITRE Corporation, the well-known research facility doing major work for the US government, is the initiator and sponsor of the CVE Program (https://cve.org). Its goal is to identify and list common vulnerabilities, thus the name CVE: Common Vulnerabilities and Exposures. The website—www.cvedetails.com/, independent of MITRE and the CVE project, but reusing its classification scheme—provides a searchable list of all reported vulnerabilities in various software products. For instance, http://mng.bz/gwDe lists all security vulnerabilities from Microsoft’s IIS (Internet Information Services), and http://mng.bz/e7j9 shows all security-related issues reported in ASP.NET Core (figure 9.1).
If you drill down in one specific CVE, you will find more details, including information about the version or patch in which the issue has been fixed.