Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product .net
Total 121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-71328 1 Microsoft 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more 2026-09-11 N/A 8.8 HIGH
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-62886 1 Microsoft 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more 2026-09-08 N/A 7.8 HIGH
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-58641 3 Apple, Linux, Microsoft 4 Macos, Linux Kernel, .net and 1 more 2026-09-03 N/A 7.8 HIGH
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2023-21808 1 Microsoft 25 .net, .net Framework, Visual Studio 2017 and 22 more 2026-08-19 N/A 7.8 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2020-1108 1 Microsoft 15 .net, .net Core, .net Framework and 12 more 2026-08-19 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
CVE-2026-70354 1 Microsoft 18 .net, .net Framework, Visual Studio 2022 and 15 more 2026-08-17 N/A 7.8 HIGH
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62898 1 Microsoft 3 .net, Visual Studio 2022, Visual Studio 2026 2026-08-14 N/A 7.5 HIGH
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897 1 Microsoft 7 .net, .net Framework, Visual Studio 2022 and 4 more 2026-08-14 N/A 7.0 HIGH
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62899 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 5.9 MEDIUM
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62900 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 5.9 MEDIUM
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 7.5 HIGH
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62902 1 Microsoft 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more 2026-08-14 N/A 6.5 MEDIUM
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62909 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-14 N/A 7.8 HIGH
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62871 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2026-08-13 N/A 7.8 HIGH
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2023-44487 33 Akka, Amazon, Apache and 30 more 324 Http Server, Opensearch Data Prepper, Apisix and 321 more 2026-08-11 N/A 7.5 HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-38180 2 Fedoraproject, Microsoft 4 Fedora, .net, Asp.net Core and 1 more 2026-08-10 N/A 7.5 HIGH
.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-38178 1 Microsoft 2 .net, Visual Studio 2022 2026-08-10 N/A 7.5 HIGH
.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-35391 1 Microsoft 3 .net, Asp.net Core, Visual Studio 2022 2026-08-10 N/A 6.2 MEDIUM
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
CVE-2023-35390 1 Microsoft 2 .net, Visual Studio 2022 2026-08-10 N/A 7.8 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2021-34485 1 Microsoft 5 .net, .net Core, Powershell Core and 2 more 2026-08-10 2.1 LOW 5.0 MEDIUM
.NET Core and Visual Studio Information Disclosure Vulnerability