Microsoft Net vulnerabilities
89 known vulnerabilities affecting microsoft/net.
Total CVEs
89
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
3
Severity breakdown
CRITICAL4HIGH69MEDIUM16
Vulnerabilities
Page 3 of 5
CVE-2025-30399P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.6≥ 8.0.0, < 8.0.172025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2025-55247P3HIGHCVSS 7.3≥ 8.0.0, < 8.0.21≥ 9.0.0, < 9.0.102025-10-14
CVE-2025-55247 [HIGH] CWE-59 CVE-2025-55247: Improper link resolution before file access ('link following') in .NET allows an authorized attacker
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
nvd
CVE-2020-1108P3HIGHCVSS 7.5v5.02020-05-21
CVE-2020-1108 [HIGH] CVE-2020-1108: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web req
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.
nvd
CVE-2023-35390P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.21≥ 7.0.0, < 7.0.102023-08-08
CVE-2023-35390 [HIGH] CWE-77 CVE-2023-35390: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-35433P3HIGHCVSS 7.3≥ 8.0.0, < 8.0.27≥ 9.0.0, < 9.0.16+1 more2026-05-12
CVE-2026-35433 [HIGH] CWE-20 CVE-2026-35433: Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2023-28260P3HIGHCVSS 7.8≥ 6.0.0, < 6.0.16≥ 7.0.0, < 7.0.52023-04-11
CVE-2023-28260 [HIGH] CVE-2023-28260: .NET DLL Hijacking Remote Code Execution Vulnerability
.NET DLL Hijacking Remote Code Execution Vulnerability
nvd
CVE-2024-21409P3HIGHCVSS 7.3≥ 6.0.0, < 6.0.29≥ 7.0.0, < 7.0.18+1 more2024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2021-31204P3HIGHCVSS 7.8≥ 5.0, ≤ 5.0.52021-05-11
CVE-2021-31204 [HIGH] CVE-2021-31204: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2023-35391P3HIGHCVSS 7.5≥ 6.0.0, < 6.0.21≥ 7.0.0, < 7.0.102023-08-08
CVE-2023-35391 [HIGH] CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2023-24936P3HIGHCVSS 7.5v6.0.0v7.0.02023-06-14
CVE-2023-24936 [HIGH] CVE-2023-24936: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5≥ 5.0, ≤ 5.0.142020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2026-50659P3MEDIUMCVSS 6.5≥ 8.0.0, < 8.0.29≥ 9.0.0, < 9.0.18+1 more2026-07-14
CVE-2026-50659 [MEDIUM] CWE-116 CVE-2026-50659: Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing ov
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2023-24897P3HIGHCVSS 7.8v6.0.0v7.0.02023-06-14
CVE-2023-24897 [HIGH] CWE-122 CVE-2023-24897: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-21808P3HIGHCVSS 7.8v6.0.0v7.0.02023-02-14
CVE-2023-21808 [HIGH] CWE-416 CVE-2023-21808: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-24895P3HIGHCVSS 7.8v6.0.0v7.0.02023-06-14
CVE-2023-24895 [HIGH] CVE-2023-24895: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-33128P3HIGHCVSS 7.3≥ 6.0.0, < 6.0.18≥ 7.0.0, < 7.0.72023-06-14
CVE-2023-33128 [HIGH] CWE-416 CVE-2023-33128: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2023-33126P3HIGHCVSS 7.3≥ 6.0.0, < 6.0.18≥ 7.0.0, < 7.0.72023-06-14
CVE-2023-33126 [HIGH] CVE-2023-33126: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2022-23267P3HIGHCVSS 7.5v5.0v6.0.02022-05-10
CVE-2022-23267 [HIGH] CVE-2022-23267: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-29117P3HIGHCVSS 7.5v5.0v6.0.02022-05-10
CVE-2022-29117 [HIGH] CWE-400 CVE-2022-29117: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2022-29145P3HIGHCVSS 7.5v5.0v6.0.02022-05-10
CVE-2022-29145 [HIGH] CWE-400 CVE-2022-29145: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd