Net
by Microsoft
Source repositories
CVEs (128)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-25667 | Hig | 0.42 | 7.5 | 0.03 | Mar 19, 2026 | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing. | ||
| CVE-2026-21218 | Hig | 0.42 | 7.5 | 0.01 | Feb 10, 2026 | Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38167 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2024 | .NET and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2024-21392 | Hig | 0.42 | 7.5 | 0.03 | Mar 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-36435 | Hig | 0.42 | 7.5 | 0.06 | Oct 10, 2023 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2023-32032 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-38013 | Hig | 0.42 | 7.5 | 0.04 | Sep 13, 2022 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2022-23267 | Hig | 0.42 | 7.5 | 0.05 | May 10, 2022 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2024-30045 | Med | 0.41 | 6.3 | 0.01 | May 14, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2026-45491 | Med | 0.40 | 6.2 | 0.00 | Jun 9, 2026 | Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2023-36558 | Med | 0.40 | 6.2 | 0.01 | Nov 14, 2023 | ASP.NET Core Security Feature Bypass Vulnerability | ||
| CVE-2023-35391 | Med | 0.40 | 6.2 | 0.02 | Aug 8, 2023 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2026-62897 | Hig | 0.39 | 7.0 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | ||
| CVE-2022-34716 | Med | 0.39 | 5.9 | 0.02 | Aug 9, 2022 | .NET Spoofing Vulnerability | ||
| CVE-2021-41355 | Med | 0.39 | 5.7 | 0.20 | Oct 13, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2021-31957 | Med | 0.39 | 5.9 | 0.05 | Jun 8, 2021 | ASP.NET Core Denial of Service Vulnerability | ||
| CVE-2024-30046 | Med | 0.38 | 5.9 | 0.02 | May 14, 2024 | Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1476 | Med | 0.36 | 5.5 | 0.01 | Aug 17, 2020 | An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an… | ||
| CVE-2026-62902 | Med | 0.35 | 6.5 | 0.01 | Aug 11, 2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2022-24512 | Med | 0.34 | 6.3 | 0.02 | Mar 9, 2022 | .NET and Visual Studio Remote Code Execution Vulnerability |
- risk 0.42cvss 7.5epss 0.03
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
- risk 0.42cvss 7.5epss 0.01
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
.NET and Visual Studio Information Disclosure Vulnerability
- risk 0.42cvss 7.5epss 0.03
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.42cvss 7.5epss 0.06
Microsoft QUIC Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
.NET and Visual Studio Elevation of Privilege Vulnerability
- risk 0.42cvss 7.5epss 0.04
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.42cvss 7.5epss 0.05
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.41cvss 6.3epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.40cvss 6.2epss 0.00
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
- risk 0.40cvss 6.2epss 0.01
ASP.NET Core Security Feature Bypass Vulnerability
- risk 0.40cvss 6.2epss 0.02
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
- risk 0.39cvss 7.0epss 0.00
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- risk 0.39cvss 5.9epss 0.02
.NET Spoofing Vulnerability
- risk 0.39cvss 5.7epss 0.20
.NET Core and Visual Studio Information Disclosure Vulnerability
- risk 0.39cvss 5.9epss 0.05
ASP.NET Core Denial of Service Vulnerability
- risk 0.38cvss 5.9epss 0.02
Visual Studio Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an…
- risk 0.35cvss 6.5epss 0.01
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
- risk 0.34cvss 6.3epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
Page 6 of 7