Net
by Microsoft
Source repositories
CVEs (124)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36435 | Hig | 0.42 | 7.5 | 0.05 | Oct 10, 2023 | Microsoft QUIC Denial of Service Vulnerability | ||
| CVE-2023-32032 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-38013 | Hig | 0.42 | 7.5 | 0.03 | Sep 13, 2022 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2022-23267 | Hig | 0.42 | 7.5 | 0.05 | May 10, 2022 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2024-30045 | Med | 0.41 | 6.3 | 0.01 | May 14, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2026-45491 | Med | 0.40 | 6.2 | 0.00 | Jun 9, 2026 | Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2023-36558 | Med | 0.40 | 6.2 | 0.01 | Nov 14, 2023 | ASP.NET Core Security Feature Bypass Vulnerability | ||
| CVE-2023-35391 | Med | 0.40 | 6.2 | 0.02 | Aug 8, 2023 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2026-62897 | Hig | 0.39 | 7.0 | 0.00 | Aug 11, 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | ||
| CVE-2022-34716 | Med | 0.39 | 5.9 | 0.02 | Aug 9, 2022 | .NET Spoofing Vulnerability | ||
| CVE-2021-41355 | Med | 0.39 | 5.7 | 0.20 | Oct 13, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2021-31957 | Med | 0.39 | 5.9 | 0.05 | Jun 8, 2021 | ASP.NET Core Denial of Service Vulnerability | ||
| CVE-2026-62900 | Med | 0.38 | 5.9 | 0.01 | Aug 11, 2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-30046 | Med | 0.38 | 5.9 | 0.02 | May 14, 2024 | Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1476 | Med | 0.36 | 5.5 | 0.01 | Aug 17, 2020 | An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an… | ||
| CVE-2026-62902 | Med | 0.35 | 6.5 | 0.01 | Aug 11, 2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2022-24512 | Med | 0.34 | 6.3 | 0.02 | Mar 9, 2022 | .NET and Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2021-34485 | Med | 0.33 | 5.0 | 0.01 | Aug 12, 2021 | .NET Core and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2026-62899 | Med | 0.31 | 5.9 | 0.01 | Aug 11, 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-55248 | Med | 0.31 | 4.8 | 0.01 | Oct 14, 2025 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. |
- risk 0.42cvss 7.5epss 0.05
Microsoft QUIC Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
.NET and Visual Studio Elevation of Privilege Vulnerability
- risk 0.42cvss 7.5epss 0.03
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.42cvss 7.5epss 0.05
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.41cvss 6.3epss 0.01
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.40cvss 6.2epss 0.00
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
- risk 0.40cvss 6.2epss 0.01
ASP.NET Core Security Feature Bypass Vulnerability
- risk 0.40cvss 6.2epss 0.02
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
- risk 0.39cvss 7.0epss 0.00
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
- risk 0.39cvss 5.9epss 0.02
.NET Spoofing Vulnerability
- risk 0.39cvss 5.7epss 0.20
.NET Core and Visual Studio Information Disclosure Vulnerability
- risk 0.39cvss 5.9epss 0.05
ASP.NET Core Denial of Service Vulnerability
- risk 0.38cvss 5.9epss 0.01
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
- risk 0.38cvss 5.9epss 0.02
Visual Studio Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulnerability, an…
- risk 0.35cvss 6.5epss 0.01
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
- risk 0.34cvss 6.3epss 0.02
.NET and Visual Studio Remote Code Execution Vulnerability
- risk 0.33cvss 5.0epss 0.01
.NET Core and Visual Studio Information Disclosure Vulnerability
- risk 0.31cvss 5.9epss 0.01
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.31cvss 4.8epss 0.01
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Page 6 of 7