.Net Framework

Vendor:

First CVE: Jul 26, 2002 · Active for 23 years

200
Total CVEs
More Total CVEs than 99% of tracked products
8.3
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact .Net Framework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 26, 2002
23 years ago
Most Recent CVE
Jul 14, 2026
11 days ago

CVE Severity & Scoring

.Net Framework200 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local37 (18.5%)
Network69 (34.5%)
Unknown93 (46.5%)
Physical0 (0.0%)
Adjacent Network1 (0.5%)
Attack Complexity
Low97 (48.5%)
High10 (5.0%)
Unknown93 (46.5%)
User Interaction
None70 (35.0%)
Unknown93 (46.5%)
Required37 (18.5%)
Privileges Required
Low19 (9.5%)
High0 (0.0%)
None88 (44.0%)
Unknown93 (46.5%)

Top CVEs

Signals from CVEs in this product scope (200 CVEs).

200 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Jan 14, 20209.899YESYES
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.
Jul 14, 20207.898YESYES
.NET Framework Information Disclosure Vulnerability
Mar 23, 20247.597YESYES
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework R
Sep 13, 20177.896YESYES
The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 20
May 13, 20157.885YESNO
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to execute a method, which allows remote attackers
Feb 12, 20149.378NOYES
Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files
Jul 10, 20077.874NOYES
ASP.NET Elevation of Privilege Vulnerability
Aug 8, 20238.871NONO
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes
Sep 22, 20106.469NOYES
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via
Sep 28, 20049.368NOYES

Exploit Exposure

Signals from CVEs in this product scope (200 CVEs).

CISA KEV
5 CVEs
2.5% of CVEs· 96th percentile
Metasploit
3 CVEs
1.5% of CVEs· 96th percentile
Nuclei
2 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
21 CVEs
10.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (200 CVEs).

Media Mentions

Signals from CVEs in this product scope (200 CVEs).

Top CNAs Publishing CVEs For .Net Framework

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.8.1507.54.0%11
4.8677.26.8%33
4.7.2827.510.0%33
4.7.1807.510.6%33
4.7847.510.9%45
4.6.2857.511.0%45
4.6.1457.414.2%34
4.6657.516.8%412
4.5.2617.619.7%411
4.5.1247.733.1%18
4.5448.030.6%19
4.0588.129.5%111
3.5.11227.721.1%518
3.51477.713.6%518
3.0687.818.1%411
2.0.50727110.08.4%00
2.01218.021.6%310
1.1387.927.9%07
1.0266.821.5%05