cbcvebase.

Microsoft Net vulnerabilities

100 known vulnerabilities affecting microsoft/net.

Total CVEs
100
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH77MEDIUM19

Vulnerabilities

Page 3 of 5
CVE-2026-62909P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-62909 [HIGH] CWE-252 CVE-2026-62909: Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50648P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50648 [HIGH] CWE-770 CVE-2026-50648: Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attack Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50525P3HIGHCVSS 7.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50525 [HIGH] CWE-770 CVE-2026-50525: Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-32177P3HIGHCVSS 7.3≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-12
CVE-2026-32177 [HIGH] CWE-20 CVE-2026-32177: Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-26131P3HIGHCVSS 7.8≥ 10.0.0, < 10.0.42026-03-10
CVE-2026-26131 [HIGH] CWE-276 CVE-2026-26131: Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally. Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-50650P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.182026-07-14
CVE-2026-50650 [HIGH] CWE-94 CVE-2026-50650: Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized a Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-62886P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-62886 [HIGH] CWE-122 CVE-2026-62886: Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2026-58641P3HIGHCVSS 7.8≥ 8.0.0, < 8.0.30≥ 9.0.0, < 9.0.19+1 more2026-08-11
CVE-2026-58641 [HIGH] CWE-190 CVE-2026-58641: Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2025-30399P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.6≥ 8.0.0, < 8.0.172025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-28260P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.16≥ 7.0.0, < 7.0.52023-04-11
CVE-2023-28260 [HIGH] CVE-2023-28260: .NET DLL Hijacking Remote Code Execution Vulnerability .NET DLL Hijacking Remote Code Execution Vulnerability
nvd
CVE-2026-35433P3HIGHCVSS 7.3≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-12
CVE-2026-35433 [HIGH] CWE-20 CVE-2026-35433: Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-35390P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.21≥ 7.0.0, < 7.0.102023-08-08
CVE-2023-35390 [HIGH] CWE-77 CVE-2023-35390: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2024-21409P3HIGHCVSS 7.3≥ 6.0.0, < 6.0.29≥ 7.0.0, < 7.0.18+1 more2024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2025-55247P3HIGHCVSS 7.3≥ 8.0.0, < 8.0.21≥ 9.0.0, < 9.0.102025-10-14
CVE-2025-55247 [HIGH] CWE-59 CVE-2025-55247: Improper link resolution before file access ('link following') in .NET allows an authorized attacker Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2021-31204P3HIGHCVSS 7.8≥ 5.0, ≤ 5.0.52021-05-11
CVE-2021-31204 [HIGH] CVE-2021-31204: .NET and Visual Studio Elevation of Privilege Vulnerability .NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-35391P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.21≥ 7.0.0, < 7.0.102023-08-08
CVE-2023-35391 [HIGH] CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5≥ 5.0, ≤ 5.0.142020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50659 [MEDIUM] CWE-116 CVE-2026-50659: Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2023-24897P3HIGHCVSS 7.8v6.0.0v7.0.02023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-21808P3HIGHCVSS 7.8v6.0.0v7.0.02023-02-14
CVE-2023-21808 [HIGH] CWE-416 CVE-2023-21808: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
Microsoft Net vulnerabilities | cvebase