Microsoft Net vulnerabilities
89 known vulnerabilities affecting microsoft/net.
Total CVEs
89
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH69MEDIUM16
Vulnerabilities
Page 1 of 5
CVE-2023-44487P1HIGHCVSS 7.5KEVPoC≥ 6.0.0, < 6.0.23≥ 7.0.0, < 7.0.122023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-38180P2HIGHCVSS 7.5KEV≥ 6.0.0, < 6.0.21≥ 7.0.0, < 7.0.102023-08-08
CVE-2023-38180 [HIGH] CWE-400 CVE-2023-38180: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2026-26127P2HIGHCVSS 7.5Exploited≥ 10.0.0, < 10.0.4≥ 9.0.0, < 9.0.142026-03-10
CVE-2026-26127 [HIGH] CWE-125 CVE-2026-26127: Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-47303P2HIGHCVSS 8.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-47303 [HIGH] CWE-90 CVE-2026-47303: Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to ele
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-43498P2CRITICALCVSS 9.8v9.0.02024-11-12
CVE-2024-43498 [CRITICAL] CWE-843 CVE-2024-43498: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-47300P2HIGHCVSS 8.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-47300 [HIGH] CWE-303 CVE-2026-47300: Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker t
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36049P3CRITICALCVSS 9.8≥ 6.0.0, < 6.0.25≥ 7.0.0, < 7.0.14+1 more2023-11-14
CVE-2023-36049 [CRITICAL] CWE-20 CVE-2023-36049: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2026-47304P3CRITICALCVSS 9.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-47304 [CRITICAL] CWE-345 CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2024-0057P3CRITICALCVSS 9.8≥ 6.0.0, < 6.0.26≥ 7.0.0, < 7.0.15+1 more2024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2025-21176P3HIGHCVSS 8.8v8.0.0v9.0.02025-01-14
CVE-2025-21176 [HIGH] CWE-126 CVE-2025-21176: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-32178P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 8.0.0, < 8.0.26+1 more2026-04-14
CVE-2026-32178 [HIGH] CWE-138 CVE-2026-32178: Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoof
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-0056P3HIGHCVSS 8.7≥ 6.0.0, < 6.0.26≥ 7.0.0, < 7.0.15+1 more2024-01-09
CVE-2024-0056 [HIGH] CWE-319 CVE-2024-0056: Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnera
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
nvd
CVE-2024-35264P3HIGHCVSS 8.1≥ 8.0.0, < 8.0.72024-07-09
CVE-2024-35264 [HIGH] CWE-416 CVE-2024-35264: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-38229P3HIGHCVSS 8.1≥ 8.0.0, < 8.0.102024-10-08
CVE-2024-38229 [HIGH] CWE-416 CVE-2024-38229: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-25667P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.22≥ 9.0.0, < 9.0.112026-03-19
CVE-2026-25667 [HIGH] CWE-400 CVE-2026-25667: ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
nvd
CVE-2026-50528P3HIGHCVSS 8.2≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50528 [HIGH] CWE-302 CVE-2026-50528: Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2026-26171P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 8.0.0, < 8.0.26+1 more2026-04-14
CVE-2026-26171 [HIGH] CWE-400 CVE-2026-26171: Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a net
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-45591P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.28≥ 9.0.0, < 9.0.17+1 more2026-06-09
CVE-2026-45591 [HIGH] CWE-400 CVE-2026-45591: Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service ov
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32203P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 8.0.0, < 8.0.26+1 more2026-04-14
CVE-2026-32203 [HIGH] CWE-20 CVE-2026-32203: Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny servic
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-33170P3HIGHCVSS 8.1≥ 6.0.0, < 6.0.20≥ 7.0.0, < 7.0.92023-07-11
CVE-2023-33170 [HIGH] CWE-362 CVE-2023-33170: ASP.NET and Visual Studio Security Feature Bypass Vulnerability
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
nvd
1 / 5Next →