.Net

Vendor:

First CVE: May 21, 2020 · Active for 6 years

108
Total CVEs
More Total CVEs than 99% of tracked products
15.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact .Net over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2020
6 years ago
Most Recent CVE
Jul 14, 2026
14 days ago

CVE Severity & Scoring

.Net108 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local31 (28.7%)
Network76 (70.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low95 (88.0%)
High13 (12.0%)
Unknown0 (0.0%)
User Interaction
None74 (68.5%)
Unknown0 (0.0%)
Required34 (31.5%)
Privileges Required
Low22 (20.4%)
High1 (0.9%)
None85 (78.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (108 CVEs).

108 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
.NET and Visual Studio Denial of Service Vulnerability
Aug 8, 20237.570YESNO
Microsoft QUIC Denial of Service Vulnerability
Oct 10, 20237.560NONO
.NET Core Remote Code Execution Vulnerability
Feb 25, 20219.847NONO
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
Jul 14, 20269.841NONO
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Jul 14, 20268.839NONO
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
Jul 14, 20268.839NONO
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Nov 14, 20239.837NONO
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Jul 14, 20268.236NONO
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
Jul 14, 20267.835NONO

Exploit Exposure

Signals from CVEs in this product scope (108 CVEs).

CISA KEV
2 CVEs
1.9% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (108 CVEs).

Media Mentions

Signals from CVEs in this product scope (108 CVEs).

Top CNAs Publishing CVEs For .Net

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.068.12.2%00
8.0.078.14.0%00
7.0.0107.61.8%00
6.0.0197.42.6%00
5.067.19.0%00