Filtered by vendor Microsoft
Subscriptions
Filtered by product .net
Subscriptions
Total
159 CVE
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-71328 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-69439 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-09-09 | 8.8 High |
| Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69806 | 1 Microsoft | 3 .net, Visual Studio 2022, Visual Studio 2026 | 2026-09-08 | 7 High |
| Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-69304 | 1 Microsoft | 4 .net, Asp.net Core, Visual Studio 2022 and 1 more | 2026-09-08 | 5.9 Medium |
| Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-58649 | 1 Microsoft | 5 .net, Microsoft Visual Studio 2022, Microsoft Visual Studio 2026 and 2 more | 2026-09-08 | 6.5 Medium |
| Origin validation error in .NET allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-69522 | 1 Microsoft | 4 .net, .net Framework, Visual Studio 2022 and 1 more | 2026-09-08 | 8.8 High |
| Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-62886 | 1 Microsoft | 7 .net, .net Framework, Microsoft Visual Studio 2022 and 4 more | 2026-09-08 | 7.8 High |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | ||||
| CVE-2026-58641 | 3 Apple, Linux, Microsoft | 5 Macos, Linux Kernel, .net and 2 more | 2026-09-03 | 7.8 High |
| Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | ||||
| CVE-2020-1108 | 2 Microsoft, Redhat | 17 .net, .net Core, .net Framework and 14 more | 2026-08-19 | 7.5 High |
| A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. | ||||
| CVE-2020-1066 | 1 Microsoft | 4 .net, .net Framework, Windows 7 and 1 more | 2026-08-19 | 7.8 High |
| An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framework activates COM objects. | ||||
| CVE-2023-21808 | 1 Microsoft | 27 .net, .net Framework, Powershell and 24 more | 2026-08-19 | 7.8 High |
| .NET and Visual Studio Remote Code Execution Vulnerability | ||||
| CVE-2026-70354 | 1 Microsoft | 20 .net, .net Framework, Microsoft Visual Studio 2022 and 17 more | 2026-08-17 | 7.8 High |
| Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-62899 | 3 Apple, Linux, Microsoft | 8 Macos, Linux Kernel, .net and 5 more | 2026-08-17 | 5.9 Medium |
| Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | ||||
| CVE-2026-62901 | 3 Apple, Linux, Microsoft | 8 Macos, Linux Kernel, .net and 5 more | 2026-08-17 | 7.5 High |
| Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-62902 | 1 Microsoft | 6 .net, Microsoft Visual Studio 2022, Microsoft Visual Studio 2026 and 3 more | 2026-08-17 | 6.5 Medium |
| Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-62909 | 3 Apple, Linux, Microsoft | 8 Macos, Linux Kernel, .net and 5 more | 2026-08-17 | 7.8 High |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | ||||
| CVE-2026-62872 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-08-14 | 8.8 High |
| Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62897 | 1 Microsoft | 7 .net, .net Framework, Visual Studio 2022 and 4 more | 2026-08-14 | 7 High |
| Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-62900 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | 5.9 Medium |
| Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-65810 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-08-14 | 7.8 High |
| Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||||