Microsoft Net
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Microsoft Net.
Recent Microsoft Net Security Advisories
| Advisory | Title | Published |
|---|---|---|
| CVE-2026-0905 | Chromium: CVE-2026-0905 Insufficient policy enforcement in Network | January 17, 2026 |
| CVE-2025-38639 | CVE-2025-38639 netfilter: xt_nfacct: don't assume acct name is null-terminated | January 8, 2026 |
| CVE-2025-68301 | CVE-2025-68301 net: atlantic: fix fragment overflow handling in RX path | January 8, 2026 |
| CVE-2025-68302 | CVE-2025-68302 net: sxgbe: fix potential NULL dereference in sxgbe_rx() | January 7, 2026 |
| CVE-2025-38400 | CVE-2025-38400 nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails. | December 25, 2025 |
| CVE-2025-38422 | CVE-2025-38422 net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices | December 25, 2025 |
| CVE-2025-38477 | CVE-2025-38477 net/sched: sch_qfq: Fix race condition on qfq_aggregate | December 25, 2025 |
| CVE-2025-68615 | CVE-2025-68615 Net-SNMP snmptrapd crash | December 25, 2025 |
| CVE-2025-38441 | CVE-2025-38441 netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() | December 24, 2025 |
| CVE-2025-38474 | CVE-2025-38474 usb: net: sierra: check for no status endpoint | December 24, 2025 |
By the Year
In 2026 there have been 0 vulnerabilities in Microsoft Net. Last year, in 2025 Net had 2 security vulnerabilities published. Right now, Net is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 2 | 6.05 |
| 2024 | 16 | 7.55 |
| 2023 | 31 | 7.54 |
| 2022 | 10 | 7.05 |
| 2021 | 8 | 6.76 |
| 2020 | 2 | 7.00 |
It may take a day or so for new Net vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Net Security Vulnerabilities
Oct 2025: .NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability
CVE-2025-55248
4.8 - Medium
- October 14, 2025
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Inadequate Encryption Strength
Oct 2025: .NET Elevation of Privilege Vulnerability
CVE-2025-55247
7.3 - High
- October 14, 2025
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
insecure temporary file
Microsoft .NET & Visual Studio Info Disclosure CVE-2024-38167
CVE-2024-38167
6.5 - Medium
- August 13, 2024
.NET and Visual Studio Information Disclosure Vulnerability
Cleartext Transmission of Sensitive Information
Denial of Service in Microsoft .NET Framework & Visual Studio
CVE-2024-38168
7.5 - High
- August 13, 2024
.NET and Visual Studio Denial of Service Vulnerability
Jul 2024: .NET and Visual Studio Denial of Service Vulnerability
CVE-2024-38095
7.5 - High
- July 09, 2024
.NET and Visual Studio Denial of Service Vulnerability
Improper Input Validation
Jul 2024: .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-35264
8.1 - High
- July 09, 2024
.NET and Visual Studio Remote Code Execution Vulnerability
Dangling pointer
Jul 2024: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
CVE-2024-38081
7.3 - High
- July 09, 2024
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
insecure temporary file
Jul 2024: .NET and Visual Studio Denial of Service Vulnerability
CVE-2024-30105
7.5 - High
- July 09, 2024
.NET and Visual Studio Denial of Service Vulnerability
Resource Exhaustion
Microsoft .NET & VS Remote Code Execution via RCE Vulnerability
CVE-2024-30045
6.3 - Medium
- May 14, 2024
.NET and Visual Studio Remote Code Execution Vulnerability
Visual Studio DoS via malformed input
CVE-2024-30046
- May 14, 2024
Visual Studio Denial of Service Vulnerability
Race Condition
Microsoft .NET Framework & Visual Studio RCE via CVE-2024-21409
CVE-2024-21409
7.3 - High
- April 09, 2024
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Mar 2024: .NET Framework Information Disclosure Vulnerability
CVE-2024-29059
7.5 - High
- March 23, 2024
.NET Framework Information Disclosure Vulnerability
Generation of Error Message Containing Sensitive Information
Microsoft QUIC DoS via malformed QUIC packets
CVE-2024-26190
7.5 - High
- March 12, 2024
Microsoft QUIC Denial of Service Vulnerability
.NET / Visual Studio DoS Vulnerability (CVE-2024-21392)
CVE-2024-21392
7.5 - High
- March 12, 2024
.NET and Visual Studio Denial of Service Vulnerability
Microsoft Identity Platform DoS Vulnerability (CVE-2024-21319)
CVE-2024-21319
6.8 - Medium
- January 09, 2024
Microsoft Identity Denial of service vulnerability
Microsoft.Data.SqlClient SQL Feature Bypass Vulnerability
CVE-2024-0056
8.7 - High
- January 09, 2024
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Microsoft .NET Framework Security Bypass CVE-2024-0057
CVE-2024-0057
9.8 - Critical
- January 09, 2024
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
.NET DoS Vulnerability (CVE-2024-20672)
CVE-2024-20672
7.5 - High
- January 09, 2024
.NET Denial of Service Vulnerability
Nov 2023: ASP.NET Core Security Feature Bypass Vulnerability
CVE-2023-36558
6.2 - Medium
- November 14, 2023
ASP.NET Core Security Feature Bypass Vulnerability
Nov 2023: ASP.NET Core Denial of Service Vulnerability
CVE-2023-36038
8.2 - High
- November 14, 2023
ASP.NET Core Denial of Service Vulnerability
Resource Exhaustion
Nov 2023: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
CVE-2023-36049
7.6 - High
- November 14, 2023
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Improper Input Validation
Nov 2023: Visual Studio Denial of Service Vulnerability
CVE-2023-36042
6.2 - Medium
- November 14, 2023
Visual Studio Denial of Service Vulnerability
Heap-based Buffer Overflow
Nov 2023: ASP.NET Security Feature Bypass Vulnerability
CVE-2023-36560
8.8 - High
- November 14, 2023
ASP.NET Security Feature Bypass Vulnerability
Microsoft QUIC component DoS via malformed packet
CVE-2023-38171
7.5 - High
- October 10, 2023
Microsoft QUIC Denial of Service Vulnerability
Microsoft QUIC Stack DoS via Unvalidated Input
CVE-2023-36435
7.5 - High
- October 10, 2023
Microsoft QUIC Denial of Service Vulnerability
HTTP/2 DoS via Stream Reset in nginx
CVE-2023-44487
7.5 - High
- October 10, 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Resource Exhaustion
Sep 2023: .NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-36799
6.5 - Medium
- September 12, 2023
.NET Core and Visual Studio Denial of Service Vulnerability
Resource Exhaustion
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36794
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Integer underflow
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36796
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Integer underflow
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36793
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Heap-based Buffer Overflow
Sep 2023: Visual Studio Remote Code Execution Vulnerability
CVE-2023-36792
7.8 - High
- September 12, 2023
Visual Studio Remote Code Execution Vulnerability
Integer Overflow or Wraparound
Sep 2023: .NET Framework Remote Code Execution Vulnerability
CVE-2023-36788
7.8 - High
- September 12, 2023
.NET Framework Remote Code Execution Vulnerability
Microsoft ASP.NET Core SignalR & VS Info Disclosure (CVE-2023-35391)
CVE-2023-35391
7.5 - High
- August 08, 2023
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
Aug 2023: .NET and Visual Studio Denial of Service Vulnerability
CVE-2023-38180
7.5 - High
- August 08, 2023
.NET and Visual Studio Denial of Service Vulnerability
Resource Exhaustion
Microsoft .NET & VS Remote Code Exec (CVE-2023-35390)
CVE-2023-35390
7.8 - High
- August 08, 2023
.NET and Visual Studio Remote Code Execution Vulnerability
DoS in .NET Core (CVE-2023-38178)
CVE-2023-38178
7.5 - High
- August 08, 2023
.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2023-33170: ASP.NET VS Security Feature Bypass
CVE-2023-33170
8.1 - High
- July 11, 2023
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
Race Condition
.NET/VS Elevation of Privilege via Internal Buffer Overflow
CVE-2023-33127
8.1 - High
- July 11, 2023
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET Framework & VS Remote Code Execution Vulnerability
CVE-2023-24897
7.8 - High
- June 14, 2023
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Microsoft .NET Framework DoS via invalid input in Visual Studio
CVE-2023-29331
7.5 - High
- June 14, 2023
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
Microsoft .NET/Visual Studio Elevation of Privilege
CVE-2023-24936
7.5 - High
- June 14, 2023
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Microsoft .NET Framework RCE Vulnerability
CVE-2023-24895
7.8 - High
- June 14, 2023
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
EOP in .NET/VS (CVE-2023-32032)
CVE-2023-32032
6.5 - Medium
- June 14, 2023
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET Framework RCE via Visual Studio RCE Exploit (CVE-2023-33126)
CVE-2023-33126
7.3 - High
- June 14, 2023
.NET and Visual Studio Remote Code Execution Vulnerability
.NET/VS RCE Vulnerability
CVE-2023-33128
7.3 - High
- June 14, 2023
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2023-33135 .NET/VS Elevation of Privilege
CVE-2023-33135
7.3 - High
- June 14, 2023
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET DLL Hijacking RCE Vulnerability
CVE-2023-28260
7.8 - High
- April 11, 2023
.NET DLL Hijacking Remote Code Execution Vulnerability
CVE-2023-21808: RCE in .NET/Visual Studio
CVE-2023-21808
7.8 - High
- February 14, 2023
.NET and Visual Studio Remote Code Execution Vulnerability
MS .NET Framework DoS Vulnerability (CVE-2023-21538)
CVE-2023-21538
7.5 - High
- January 10, 2023
.NET Denial of Service Vulnerability
NuGet Client EoP Vulnerability
CVE-2022-41032
7.8 - High
- October 11, 2022
NuGet Client Elevation of Privilege Vulnerability
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Net or by Microsoft? Click the Watch button to subscribe.