Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product .net Framework
Total 204 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-21808 1 Microsoft 25 .net, .net Framework, Visual Studio 2017 and 22 more 2026-08-19 N/A 7.8 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2023-21722 1 Microsoft 22 .net Framework, Windows 10 1507, Windows 10 1511 and 19 more 2026-08-19 N/A 5.0 MEDIUM
.NET Framework Denial of Service Vulnerability
CVE-2020-1108 1 Microsoft 15 .net, .net Core, .net Framework and 12 more 2026-08-19 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
CVE-2020-1066 1 Microsoft 3 .net Framework, Windows 7, Windows Server 2008 2026-08-19 4.6 MEDIUM 7.8 HIGH
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects.
CVE-2026-70354 1 Microsoft 18 .net, .net Framework, Visual Studio 2022 and 15 more 2026-08-17 N/A 7.8 HIGH
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62872 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-08-14 N/A 8.8 HIGH
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
CVE-2026-62897 1 Microsoft 7 .net, .net Framework, Visual Studio 2022 and 4 more 2026-08-14 N/A 7.0 HIGH
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-65810 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-08-14 N/A 7.8 HIGH
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2023-36899 1 Microsoft 10 .net Framework, Windows 10 1809, Windows 10 21h2 and 7 more 2026-08-10 N/A 8.8 HIGH
ASP.NET Elevation of Privilege Vulnerability
CVE-2023-36873 1 Microsoft 12 .net Framework, Windows 10 1607, Windows 10 1809 and 9 more 2026-08-10 N/A 7.4 HIGH
.NET Framework Spoofing Vulnerability
CVE-2022-41064 1 Microsoft 12 .net Framework, Nuget, Windows 10 and 9 more 2026-08-10 N/A 5.8 MEDIUM
.NET Framework Information Disclosure Vulnerability
CVE-2026-32226 1 Microsoft 7 .net Framework, Windows 10 1607, Windows 10 1809 and 4 more 2026-07-25 N/A 5.9 MEDIUM
Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-33116 3 Apple, Linux, Microsoft 18 Macos, Linux Kernel, .net and 15 more 2026-07-25 N/A 7.5 HIGH
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-50652 1 Microsoft 14 .net Framework, Azure Active Directory, Windows 10 1607 and 11 more 2026-07-24 N/A 7.5 HIGH
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50653 1 Microsoft 14 .net Framework, Azure Active Directory, Windows 10 1607 and 11 more 2026-07-24 N/A 7.5 HIGH
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50355 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-07-24 N/A 7.5 HIGH
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50368 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-07-24 N/A 7.5 HIGH
Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.
CVE-2026-50411 1 Microsoft 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more 2026-07-24 N/A 7.5 HIGH
Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.
CVE-2026-50650 1 Microsoft 15 .net, .net Framework, Windows and 12 more 2026-07-24 N/A 7.8 HIGH
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50649 1 Microsoft 16 .net, .net Framework, Visual Studio 2026 and 13 more 2026-07-24 N/A 7.8 HIGH
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.