Net
Vendor:
First CVE: Sep 16, 2018 · Active for 7 years
12
Total CVEs
More Total CVEs than 90% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Net over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 16, 2018
7 years ago
Most Recent CVE
May 22, 2026
63 days ago
CVE Severity & Scoring
Net12 CVEs
42%
50%
8%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (58.3%)
Unknown0 (0.0%)
Required5 (41.7%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None11 (91.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39821CRITICAL The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns th | May 22, 2026 | 9.6 | 46 | NO | NO |
CVE-2026-25680MEDIUM Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service. | May 22, 2026 | 6.5 | 36 | NO | NO |
CVE-2026-27136MEDIUM Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanit | May 22, 2026 | 6.1 | 35 | NO | NO |
CVE-2026-25681MEDIUM Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanit | May 22, 2026 | 6.1 | 35 | NO | NO |
CVE-2026-42502MEDIUM Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanit | May 22, 2026 | 6.1 | 34 | NO | NO |
CVE-2026-42506MEDIUM Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanit | May 22, 2026 | 6.1 | 34 | NO | NO |
CVE-2018-17142HIGH The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an | Sep 17, 2018 | 7.5 | 26 | NO | NO |
CVE-2018-17848HIGH The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionMod | Oct 1, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-17847HIGH The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeSt | Oct 1, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-17846HIGH The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSel | Oct 1, 2018 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Net
Top CWEs
Versions
No cataloged versions.