Net
by Microsoft
Source repositories
CVEs (124)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-26131 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. | ||
| CVE-2023-36796 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36794 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36793 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-36792 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-35390 | Hig | 0.51 | 7.8 | 0.02 | Aug 8, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-24897 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-24895 | Hig | 0.51 | 7.8 | 0.01 | Jun 14, 2023 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-28260 | Hig | 0.51 | 7.8 | 0.02 | Apr 11, 2023 | .NET DLL Hijacking Remote Code Execution Vulnerability | ||
| CVE-2023-21808 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2020-1046 | Hig | 0.51 | 7.8 | 0.04 | Aug 17, 2020 | A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially… | ||
| CVE-2023-36049 | Hig | 0.50 | 7.6 | 0.13 | Nov 14, 2023 | .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2020-1108 | Hig | 0.50 | 7.5 | 0.12 | May 21, 2020 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. | ||
| CVE-2026-50651 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50648 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50527 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50525 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50524 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-47302 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-57108 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network. |
- risk 0.51cvss 7.8epss 0.00
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
.NET DLL Hijacking Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.04
A remote code execution vulnerability exists when Microsoft .NET Framework processes input. An attacker who successfully exploited this vulnerability could take control of an affected system. To exploit the vulnerability, an attacker would need to be able to upload a specially…
- risk 0.50cvss 7.6epss 0.13
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
- risk 0.50cvss 7.5epss 0.12
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Page 2 of 7