Microsoft Net vulnerabilities
89 known vulnerabilities affecting microsoft/net.
Total CVEs
89
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH69MEDIUM16
Vulnerabilities
Page 2 of 5
CVE-2026-42899P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-12
CVE-2026-42899 [HIGH] CWE-835 CVE-2026-42899: Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attack
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-33116P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 8.0.0, < 8.0.26+1 more2026-04-14
CVE-2026-33116 [HIGH] CWE-20 CVE-2026-33116: Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-21172P3HIGHCVSS 7.5v8.0.0v9.0.02025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-57108P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-57108 [HIGH] CWE-843 CVE-2026-57108: Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized at
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-21218P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.24≥ 9.0.0, < 9.0.13+1 more2026-02-10
CVE-2026-21218 [HIGH] CWE-166 CVE-2026-21218: Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoo
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-56170P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-56170 [HIGH] CWE-770 CVE-2026-56170: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50527P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50527 [HIGH] CWE-121 CVE-2026-50527: Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50524P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50524 [HIGH] CWE-1287 CVE-2026-50524: Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2023-33127P3HIGHCVSS 8.1≥ 6.0.0, < 6.0.20≥ 7.0.0, < 7.0.92023-07-11
CVE-2023-33127 [HIGH] CWE-1220 CVE-2023-33127: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2026-50649P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.182026-07-14
CVE-2026-50649 [HIGH] CWE-502 CVE-2026-50649: Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45490P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.28≥ 9.0.0, < 9.0.17+1 more2026-06-09
CVE-2026-45490 [HIGH] CWE-285 CVE-2026-45490: Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47302P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-47302 [HIGH] CWE-770 CVE-2026-47302: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50651P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50651 [HIGH] CWE-770 CVE-2026-50651: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2025-26646P3HIGHCVSS 8.0≥ 9.0.0, < 9.0.5≥ 8.0.0, < 8.0.162025-05-13
CVE-2025-26646 [HIGH] CWE-73 CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allo
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-50646P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.182026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32177P3HIGHCVSS 7.3≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-12
CVE-2026-32177 [HIGH] CWE-20 CVE-2026-32177: Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-26131P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.42026-03-10
CVE-2026-26131 [HIGH] CWE-276 CVE-2026-26131: Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50650P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.182026-07-14
CVE-2026-50650 [HIGH] CWE-94 CVE-2026-50650: Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
nvd