📦 .net

by Microsoft

🔍 What is .net?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-0057

CRITICAL CVSS 9.1 Jan 9, 2024

This vulnerability allows attackers to bypass security features in .NET, .NET Framework, and Visual Studio, potentially enabling unauthorized access or privilege escalation. It affects systems running...

CVE-2026-21218

HIGH CVSS 7.5 Feb 10, 2026

This .NET vulnerability allows unauthorized attackers to perform spoofing attacks over a network by exploiting improper handling of missing special elements. It affects systems running vulnerable vers...

CVE-2025-30399

HIGH CVSS 7.5 Jun 13, 2025

This CVE describes an untrusted search path vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code by manipulating the search order for DLLs or other files. Attackers ...

CVE-2025-26646

HIGH CVSS 8.0 May 13, 2025

This vulnerability allows an authorized attacker to control file names or paths in .NET, Visual Studio, and Build Tools for Visual Studio, enabling network-based spoofing attacks. It affects systems r...

CVE-2025-21171

HIGH CVSS 7.5 Jan 14, 2025

This .NET vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a heap-based buffer overflow. It affects systems running vulnerable versions of .NET Framewo...

CVE-2025-21172

HIGH CVSS 7.5 Jan 14, 2025

This CVE describes a heap-based buffer overflow vulnerability in .NET and Visual Studio that could allow remote code execution. Attackers could exploit this by tricking users into opening specially cr...

CVE-2025-21173

HIGH CVSS 7.3 Jan 14, 2025

This CVE describes a privilege escalation vulnerability in .NET that allows authenticated attackers to elevate their privileges on affected systems. It affects systems running vulnerable versions of ....

CVE-2025-21176

HIGH CVSS 8.8 Jan 14, 2025

This vulnerability allows remote code execution in .NET, .NET Framework, and Visual Studio applications through a buffer overflow condition (CWE-126). Attackers can exploit this to execute arbitrary c...

CVE-2024-43483

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability in .NET, .NET Framework, and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected applications. It affects systems running v...

CVE-2024-43485

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests that trigger inefficient algorithmic complexity. It affects systems run...

CVE-2024-38168

HIGH CVSS 7.5 Aug 13, 2024

This CVE describes a denial of service vulnerability in .NET and Visual Studio where an attacker can cause affected systems to become unresponsive or crash. The vulnerability affects systems running v...

CVE-2024-38095

HIGH CVSS 7.5 Jul 9, 2024

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. It affects applications built with vulnerable .NET...

CVE-2024-38081

HIGH CVSS 7.3 Jul 9, 2024

This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, or Visual Studio installations. An authenticated attacker could exploit this to gain higher ...

CVE-2024-21409

HIGH CVSS 7.3 Apr 9, 2024

This vulnerability allows remote code execution in .NET, .NET Framework, and Visual Studio through a use-after-free memory corruption issue (CWE-416). Attackers can exploit this to execute arbitrary c...

CVE-2024-26190

HIGH CVSS 7.5 Mar 12, 2024

This vulnerability in Microsoft's QUIC protocol implementation allows attackers to cause denial of service by sending specially crafted network packets. It affects systems running Microsoft Windows wi...

CVE-2024-21392

HIGH CVSS 7.5 Mar 12, 2024

This vulnerability in .NET and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected systems. It affects applications built with vulnerable .NET...

CVE-2024-20672

HIGH CVSS 7.5 Jan 9, 2024

This CVE describes a denial of service vulnerability in .NET that allows attackers to crash affected applications by sending specially crafted requests. It affects systems running vulnerable versions ...

CVE-2023-36049

HIGH CVSS 7.6 Nov 14, 2023

This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, and Visual Studio versions. An authenticated attacker could exploit this to gain higher priv...

CVE-2023-38171

HIGH CVSS 7.5 Oct 10, 2023

This vulnerability in Microsoft's QUIC protocol implementation allows attackers to cause denial of service by sending specially crafted network packets. It affects Windows systems running QUIC-enabled...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2023-36796

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability in Visual Studio allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted file. It affects developers and organizations usin...

CVE-2023-36793

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability allows remote code execution in Visual Studio when processing specially crafted files. Attackers could exploit this to run arbitrary code on affected systems. Users running vulnerab...

CVE-2023-38180

HIGH CVSS 7.5 Aug 8, 2023

This CVE describes a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending specially crafted requests. It affects systems running vu...

CVE-2023-35390

HIGH CVSS 7.8 Aug 8, 2023

CVE-2023-35390 is a remote code execution vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code on affected systems. The vulnerability affects systems running vulnera...

CVE-2023-33170

HIGH CVSS 8.1 Jul 11, 2023

This vulnerability allows attackers to bypass security features in ASP.NET and Visual Studio, potentially enabling unauthorized access or privilege escalation. It affects systems running vulnerable ve...

CVE-2023-24895

HIGH CVSS 7.8 Jun 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a flaw in .NET, .NET Framework, and Visual Studio. It affects systems running vulnerable versions...

CVE-2023-24936

HIGH CVSS 7.5 Jun 14, 2023

This vulnerability allows attackers to elevate privileges on affected .NET, .NET Framework, and Visual Studio installations. An authenticated attacker could exploit this to gain higher privileges than...

CVE-2023-33126

HIGH CVSS 7.3 Jun 14, 2023

CVE-2023-33126 is a remote code execution vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code on affected systems. This affects systems running vulnerable versions ...

CVE-2023-28260

HIGH CVSS 7.8 Apr 11, 2023

CVE-2023-28260 is a .NET DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing malicious DLLs in specific directories. This affects .NET applications running on Window...

CVE-2022-29145

HIGH CVSS 7.5 May 10, 2022

CVE-2022-29145 is a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending specially crafted requests. This affects systems running v...

CVE-2022-29117

HIGH CVSS 7.5 May 10, 2022

CVE-2022-29117 is a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending specially crafted requests. This affects systems running v...

CVE-2022-23267

HIGH CVSS 7.5 May 10, 2022

This CVE describes a denial of service vulnerability in .NET and Visual Studio where an attacker could cause affected applications to crash or become unresponsive. The vulnerability affects systems ru...

CVE-2022-24464

HIGH CVSS 7.5 Mar 9, 2022

CVE-2022-24464 is a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending specially crafted requests. This affects systems running v...

CVE-2022-21986

HIGH CVSS 7.5 Feb 9, 2022

CVE-2022-21986 is a denial of service vulnerability in .NET Core and .NET 5/6 that allows attackers to crash applications by sending specially crafted requests. This affects web applications and servi...

CVE-2021-26423

HIGH CVSS 7.5 Aug 12, 2021

CVE-2021-26423 is a denial-of-service vulnerability in .NET Core and Visual Studio where an attacker can cause the application to crash by sending specially crafted requests. This affects applications...

CVE-2021-31204

HIGH CVSS 7.3 May 11, 2021

CVE-2021-31204 is an elevation of privilege vulnerability in .NET Core and Visual Studio that allows authenticated attackers to execute arbitrary code with higher privileges than intended. This affect...

CVE-2025-55248

MEDIUM CVSS 4.8 Oct 14, 2025

This vulnerability involves inadequate encryption strength in .NET, .NET Framework, and Visual Studio, allowing an authorized attacker to disclose sensitive information over a network. It affects syst...

CVE-2024-38167

MEDIUM CVSS 6.5 Aug 13, 2024

This vulnerability in .NET and Visual Studio allows attackers to read sensitive information from memory that should be protected. It affects applications built with vulnerable .NET versions and develo...

CVE-2024-30046

MEDIUM CVSS 5.9 May 14, 2024

This CVE describes a denial of service vulnerability in Visual Studio where a race condition (CWE-362) could allow an attacker to crash the application. This affects developers and organizations using...