Total
121 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-71328 | 1 Microsoft | 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more | 2026-09-11 | N/A | 8.8 HIGH |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-62886 | 1 Microsoft | 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more | 2026-09-08 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2026-58641 | 3 Apple, Linux, Microsoft | 4 Macos, Linux Kernel, .net and 1 more | 2026-09-03 | N/A | 7.8 HIGH |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2023-21808 | 1 Microsoft | 25 .net, .net Framework, Visual Studio 2017 and 22 more | 2026-08-19 | N/A | 7.8 HIGH |
| .NET and Visual Studio Remote Code Execution Vulnerability | |||||
| CVE-2020-1108 | 1 Microsoft | 15 .net, .net Core, .net Framework and 12 more | 2026-08-19 | 5.0 MEDIUM | 7.5 HIGH |
| A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. | |||||
| CVE-2026-70354 | 1 Microsoft | 18 .net, .net Framework, Visual Studio 2022 and 15 more | 2026-08-17 | N/A | 7.8 HIGH |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-62898 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-08-14 | N/A | 7.5 HIGH |
| Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-62897 | 1 Microsoft | 7 .net, .net Framework, Visual Studio 2022 and 4 more | 2026-08-14 | N/A | 7.0 HIGH |
| Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-62899 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | N/A | 5.9 MEDIUM |
| Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | |||||
| CVE-2026-62900 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | N/A | 5.9 MEDIUM |
| Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-62901 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | N/A | 7.5 HIGH |
| Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | |||||
| CVE-2026-62902 | 1 Microsoft | 4 .net, Visual Studio 2022, Visual Studio 2026 and 1 more | 2026-08-14 | N/A | 6.5 MEDIUM |
| Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-62909 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-62871 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-13 | N/A | 7.8 HIGH |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |||||
| CVE-2023-44487 | 33 Akka, Amazon, Apache and 30 more | 324 Http Server, Opensearch Data Prepper, Apisix and 321 more | 2026-08-11 | N/A | 7.5 HIGH |
| The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |||||
| CVE-2023-38180 | 2 Fedoraproject, Microsoft | 4 Fedora, .net, Asp.net Core and 1 more | 2026-08-10 | N/A | 7.5 HIGH |
| .NET and Visual Studio Denial of Service Vulnerability | |||||
| CVE-2023-38178 | 1 Microsoft | 2 .net, Visual Studio 2022 | 2026-08-10 | N/A | 7.5 HIGH |
| .NET Core and Visual Studio Denial of Service Vulnerability | |||||
| CVE-2023-35391 | 1 Microsoft | 3 .net, Asp.net Core, Visual Studio 2022 | 2026-08-10 | N/A | 6.2 MEDIUM |
| ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | |||||
| CVE-2023-35390 | 1 Microsoft | 2 .net, Visual Studio 2022 | 2026-08-10 | N/A | 7.8 HIGH |
| .NET and Visual Studio Remote Code Execution Vulnerability | |||||
| CVE-2021-34485 | 1 Microsoft | 5 .net, .net Core, Powershell Core and 2 more | 2026-08-10 | 2.1 LOW | 5.0 MEDIUM |
| .NET Core and Visual Studio Information Disclosure Vulnerability | |||||
