📦 .net Framework

by Microsoft

🔍 What is .net Framework?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-0057

CRITICAL CVSS 9.1 Jan 9, 2024

This vulnerability allows attackers to bypass security features in .NET, .NET Framework, and Visual Studio, potentially enabling unauthorized access or privilege escalation. It affects systems running...

CVE-2025-21176

HIGH CVSS 8.8 Jan 14, 2025

This vulnerability allows remote code execution in .NET, .NET Framework, and Visual Studio applications through a buffer overflow condition (CWE-126). Attackers can exploit this to execute arbitrary c...

CVE-2024-43483

HIGH CVSS 7.5 Oct 8, 2024

This vulnerability in .NET, .NET Framework, and Visual Studio allows attackers to cause a denial of service by sending specially crafted requests to affected applications. It affects systems running v...

CVE-2024-38081

HIGH CVSS 7.3 Jul 9, 2024

This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, or Visual Studio installations. An authenticated attacker could exploit this to gain higher ...

CVE-2024-21409

HIGH CVSS 7.3 Apr 9, 2024

This vulnerability allows remote code execution in .NET, .NET Framework, and Visual Studio through a use-after-free memory corruption issue (CWE-416). Attackers can exploit this to execute arbitrary c...

CVE-2024-21312

HIGH CVSS 7.5 Jan 9, 2024

This CVE describes a denial of service vulnerability in the .NET Framework where improper input validation allows attackers to crash applications. It affects systems running vulnerable versions of .NE...

CVE-2023-36049

HIGH CVSS 7.6 Nov 14, 2023

This vulnerability allows attackers to elevate privileges on systems running affected .NET, .NET Framework, and Visual Studio versions. An authenticated attacker could exploit this to gain higher priv...

CVE-2023-36796

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability in Visual Studio allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted file. It affects developers and organizations usin...

CVE-2023-36788

HIGH CVSS 7.8 Sep 12, 2023

CVE-2023-36788 is a remote code execution vulnerability in the .NET Framework that allows an attacker to execute arbitrary code on a target system by sending specially crafted requests. This affects s...

CVE-2023-36793

HIGH CVSS 7.8 Sep 12, 2023

This vulnerability allows remote code execution in Visual Studio when processing specially crafted files. Attackers could exploit this to run arbitrary code on affected systems. Users running vulnerab...

CVE-2023-36873

HIGH CVSS 7.4 Aug 8, 2023

CVE-2023-36873 is a spoofing vulnerability in the .NET Framework that allows attackers to manipulate data or impersonate legitimate sources. This affects systems running vulnerable versions of .NET Fr...

CVE-2023-24895

HIGH CVSS 7.8 Jun 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected systems by exploiting a flaw in .NET, .NET Framework, and Visual Studio. It affects systems running vulnerable versions...

CVE-2023-24936

HIGH CVSS 7.5 Jun 14, 2023

This vulnerability allows attackers to elevate privileges on affected .NET, .NET Framework, and Visual Studio installations. An authenticated attacker could exploit this to gain higher privileges than...

CVE-2023-29326

HIGH CVSS 7.8 Jun 14, 2023

This CVE describes a remote code execution vulnerability in the .NET Framework that allows an attacker to execute arbitrary code on affected systems. It affects systems running vulnerable versions of ...

CVE-2023-32030

HIGH CVSS 7.5 Jun 14, 2023

CVE-2023-32030 is a denial of service vulnerability in .NET and Visual Studio that allows attackers to crash affected applications by sending specially crafted requests. This affects systems running v...

CVE-2022-26832

HIGH CVSS 7.5 Apr 15, 2022

CVE-2022-26832 is a denial of service vulnerability in the .NET Framework where an attacker can cause a service to crash by sending specially crafted requests. This affects systems running vulnerable ...

CVE-2020-1046

HIGH CVSS 7.8 Aug 17, 2020

This CVE describes a remote code execution vulnerability in Microsoft .NET Framework that allows attackers to execute arbitrary code by uploading specially crafted files to vulnerable web applications...

CVE-2025-55248

MEDIUM CVSS 4.8 Oct 14, 2025

This vulnerability involves inadequate encryption strength in .NET, .NET Framework, and Visual Studio, allowing an authorized attacker to disclose sensitive information over a network. It affects syst...

CVE-2020-16937

MEDIUM CVSS 4.7 Oct 16, 2020

This CVE-2020-16937 is a .NET Framework memory handling vulnerability that allows authenticated attackers to read sensitive information from system memory by running specially crafted applications. It...