VulnSea

.net_8.0 vulnerabilities

CVEs whose affected-version data names the .net_8.0 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

30 CVEsRSS

CVE-2026-69522High· 8.8
1w ago

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.80%via NVD
CVE-2026-69439High· 8.8
1w ago

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.74%via NVD
CVE-2026-69304Medium· 5.9
1w ago

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.77%via NVD
CVE-2026-58649Medium· 6.5
1w ago

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.27%via NVD
CVE-2026-62900Medium· 5.9
1mo ago

.NET Information Disclosure Vulnerability

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.55%via CVEORG
CVE-2026-62902Medium· 6.5
1mo ago

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 8.0EPSS 0.78%via CVEORG
CVE-2026-62901High· 7.5
1mo ago

.NET Denial of Service Vulnerability

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-62909High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-70354High· 7.8
1mo ago

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-62897High· 7.0
1mo ago

.NET Framework Remote Code Execution Vulnerability

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.34%via CVEORG
CVE-2026-62871High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 8.0EPSS 0.40%via CVEORG
CVE-2026-62898High· 7.5
1mo ago

Microsoft QUIC Information Disclosure Vulnerability

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-62899Medium· 5.9
1mo ago

.NET Security Feature Bypass Vulnerability

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.71%via CVEORG
CVE-2026-50649High· 7.8
2mo ago

.NET Remote Code Execution Vulnerability

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 8.0EPSS 0.94%via CVEORG
CVE-2026-50646High· 7.8
2mo ago

.NET Framework Remote Code Execution Vulnerability

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 8.0EPSS 0.97%via CVEORG
CVE-2026-50650High· 7.8
2mo ago

.NET Framework Elevation of Privilege Vulnerability

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

TwilightMicrosoft · .NET 8.0EPSS 0.30%via CVEORG
CVE-2026-50527High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-47303High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.74%via CVEORG
CVE-2026-47300High· 8.8
2mo ago

ASP.NET Core Elevation of Privilege Vulnerability

Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.53%via CVEORG
CVE-2026-50526High· 7.0
2mo ago

.NET Tampering Vulnerability

Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.

TwilightMicrosoft · .NET 10.0EPSS 0.23%via CVEORG
CVE-2026-56170High· 7.5
2mo ago

ASP.NET Core Denial of Service Vulnerability

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.0%via CVEORG
CVE-2026-47304High· 8.1
2mo ago

.NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.22%via CVEORG
CVE-2026-50524High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.63%via CVEORG
CVE-2026-50648High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-50528High· 8.2
2mo ago

.NET Security Feature Bypass Vulnerability

Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.56%via CVEORG
CVE-2026-50525High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.60%via CVEORG
CVE-2026-50659Medium· 6.5
2mo ago

.NET Spoofing Vulnerability

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.55%via CVEORG
CVE-2026-50651High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-57108High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-47302High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.0%via CVEORG
.net_8.0 vulnerabilities (CVEs) · VulnSea