Microsoft Net 9.0 vulnerabilities
16 known vulnerabilities affecting microsoft/net_9.0.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH14MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-33116HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-33116 [HIGH] CWE-20 CVE-2026-33116: Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-26171HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-26171 [HIGH] CWE-400 CVE-2026-26171: Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a net
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-32203HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-32203 [HIGH] CWE-20 CVE-2026-32203: Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny servic
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-32178HIGHCVSS 7.5≥ 9.0.0, < 9.0.152026-04-14
CVE-2026-32178 [HIGH] CWE-138 CVE-2026-32178: Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoof
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2026-26127HIGHCVSS 7.5≥ 9.0.0, < 9.0.142026-03-10
CVE-2026-26127 [HIGH] CWE-125 CVE-2026-26127: Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2026-21218HIGHCVSS 7.5≥ 9.0.0, < 9.0.132026-02-10
CVE-2026-21218 [HIGH] CWE-166 CVE-2026-21218: Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoo
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2025-55247HIGHCVSS 7.3≥ 9.0.0, < 9.0.102025-10-14
CVE-2025-55247 [HIGH] CWE-59 CVE-2025-55247: Improper link resolution before file access ('link following') in .NET allows an authorized attacker
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
cvelistv5nvd
CVE-2025-55248MEDIUMCVSS 5.7≥ 9.0.0, < 9.0.102025-10-14
CVE-2025-55248 [MEDIUM] CWE-326 CVE-2025-55248: Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
cvelistv5nvd
CVE-2025-30399HIGHCVSS 7.5≥ 9.0.0, < 9.0.62025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-26646HIGHCVSS 8.0≥ 9.0.0, < 9.0.52025-05-13
CVE-2025-26646 [HIGH] CWE-73 CVE-2025-26646: External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allo
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2025-21176HIGHCVSS 8.8≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21176 [HIGH] CWE-126 .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21173HIGHCVSS 7.3≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21173 [HIGH] CWE-379 .NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
.NET Elevation of Privilege Vulnerability
cvelistv5
CVE-2025-21171HIGHCVSS 7.5≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21171 [HIGH] CWE-122 .NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
.NET Remote Code Execution Vulnerability
cvelistv5
CVE-2025-21172HIGHCVSS 7.5≥ 9.0.0, < 9.0.12025-01-14
CVE-2025-21172 [HIGH] CWE-190 .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5
CVE-2024-43498CRITICALCVSS 9.8≥ 9.0.0, < 9.0.02024-11-12
CVE-2024-43498 [CRITICAL] CWE-843 CVE-2024-43498: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
cvelistv5nvd
CVE-2024-43499HIGHCVSS 7.5≥ 9.0.0, < 9.0.02024-11-12
CVE-2024-43499 [HIGH] CWE-409 CVE-2024-43499: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
cvelistv5nvd