cbcvebase.

Microsoft Net vulnerabilities

100 known vulnerabilities affecting microsoft/net.

Total CVEs
100
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH77MEDIUM19

Vulnerabilities

Page 2 of 5
CVE-2026-42899P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-12
CVE-2026-42899 [HIGH] CWE-835 CVE-2026-42899: Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attack Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-62898P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-62898 [HIGH] CWE-416 CVE-2026-62898: Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a netw Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-33116P3HIGHCVSS 7.5≥ 10.0.0, < 10.0.6≥ 8.0.0, < 8.0.26+1 more2026-04-14
CVE-2026-33116 [HIGH] CWE-20 CVE-2026-33116: Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-70354P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-70354 [HIGH] CWE-787 CVE-2026-70354: Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-21172P3HIGHCVSS 7.5v8.0.0v9.0.02025-01-14
CVE-2025-21172 [HIGH] CWE-122 CVE-2025-21172: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-57108P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-57108 [HIGH] CWE-843 CVE-2026-57108: Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized at Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-62901P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-62901 [HIGH] CWE-606 CVE-2026-62901: Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a ne Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-21218P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.24≥ 9.0.0, < 9.0.13+1 more2026-02-10
CVE-2026-21218 [HIGH] CWE-166 CVE-2026-21218: Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoo Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-56170P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-56170 [HIGH] CWE-770 CVE-2026-56170: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50527P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50527 [HIGH] CWE-121 CVE-2026-50527: Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2020-1108P3HIGHCVSS 7.5v5.0-preview1v5.0-preview2+1 more2020-05-21
CVE-2020-1108 [HIGH] CVE-2020-1108: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web req A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could ex
nvd
CVE-2023-33127P3HIGHCVSS 8.1≥ 6.0.0, < 6.0.20≥ 7.0.0, < 7.0.92023-07-11
CVE-2023-33127 [HIGH] CWE-1220 CVE-2023-33127: .NET and Visual Studio Elevation of Privilege Vulnerability .NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2025-26646P3HIGHCVSS 8.0≥ 9.0.0, < 9.0.5≥ 8.0.0, < 8.0.162025-05-13
CVE-2025-26646 [HIGH] CWE-73 CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allo External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-50649P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.182026-07-14
CVE-2026-50649 [HIGH] CWE-502 CVE-2026-50649: Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-62871P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-62871 [HIGH] CWE-122 CVE-2026-62871: Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-45490P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.28≥ 9.0.0, < 9.0.17+1 more2026-06-09
CVE-2026-45490 [HIGH] CWE-285 CVE-2026-45490: Improper authorization in .NET allows an authorized attacker to elevate privileges locally. Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47302P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-47302 [HIGH] CWE-770 CVE-2026-47302: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50651P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50651 [HIGH] CWE-770 CVE-2026-50651: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50524P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50524 [HIGH] CWE-1287 CVE-2026-50524: Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50646P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.182026-07-14
CVE-2026-50646 [HIGH] CWE-502 CVE-2026-50646: Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code local Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
nvd
Microsoft Net vulnerabilities | cvebase