.Net
Vendor:
First CVE: May 21, 2020 · Active for 6 years
108
Total CVEs
More Total CVEs than 99% of tracked products
15.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 52% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact .Net over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2020
6 years ago
Most Recent CVE
Jul 14, 2026
14 days ago
CVE Severity & Scoring
.Net108 CVEs
17%
78%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local31 (28.7%)
Network76 (70.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.9%)
Attack Complexity
Low95 (88.0%)
High13 (12.0%)
Unknown0 (0.0%)
User Interaction
None74 (68.5%)
Unknown0 (0.0%)
Required34 (31.5%)
Privileges Required
Low22 (20.4%)
High1 (0.9%)
None85 (78.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (108 CVEs).
108 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2023-38180HIGH .NET and Visual Studio Denial of Service Vulnerability | Aug 8, 2023 | 7.5 | 70 | YES | NO |
CVE-2023-38171HIGH Microsoft QUIC Denial of Service Vulnerability | Oct 10, 2023 | 7.5 | 60 | NO | NO |
CVE-2021-26701CRITICAL .NET Core Remote Code Execution Vulnerability | Feb 25, 2021 | 9.8 | 47 | NO | NO |
CVE-2026-47304CRITICAL Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-47303HIGH Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-47300HIGH Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | Jul 14, 2026 | 8.8 | 39 | NO | NO |
CVE-2023-36049CRITICAL .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | Nov 14, 2023 | 9.8 | 37 | NO | NO |
CVE-2026-50528HIGH Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-50650HIGH Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | Jul 14, 2026 | 7.8 | 35 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (108 CVEs).
CISA KEV
2 CVEs
1.9% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (108 CVEs).
Media Mentions
Signals from CVEs in this product scope (108 CVEs).
Top CNAs Publishing CVEs For .Net
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.0 | 6 | 8.1 | 2.2% | 0 | 0 |
| 8.0.0 | 7 | 8.1 | 4.0% | 0 | 0 |
| 7.0.0 | 10 | 7.6 | 1.8% | 0 | 0 |
| 6.0.0 | 19 | 7.4 | 2.6% | 0 | 0 |
| 5.0 | 6 | 7.1 | 9.0% | 0 | 0 |