VulnSea

.net_framework_3.5 vulnerabilities

CVEs whose affected-version data names the .net_framework_3.5 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

15 CVEsRSS

CVE-2026-62872High· 8.8
1mo ago

.NET Framework Elevation of Privilege Vulnerability

Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

TwilightMicrosoft · Microsoft .NET Framework 3.5EPSS 0.54%via CVEORG
CVE-2026-65810High· 7.8
1mo ago

.NET Framework Elevation of Privilege Vulnerability

Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.

TwilightMicrosoft · Microsoft .NET Framework 3.5EPSS 0.27%via CVEORG
CVE-2026-70354High· 7.8
1mo ago

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-62897High· 7.0
1mo ago

.NET Framework Remote Code Execution Vulnerability

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.34%via CVEORG
CVE-2026-50649High· 7.8
2mo ago

.NET Remote Code Execution Vulnerability

Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 8.0EPSS 0.94%via CVEORG
CVE-2026-50646High· 7.8
2mo ago

.NET Framework Remote Code Execution Vulnerability

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 8.0EPSS 0.97%via CVEORG
CVE-2026-50650High· 7.8
2mo ago

.NET Framework Elevation of Privilege Vulnerability

Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.

TwilightMicrosoft · .NET 8.0EPSS 0.30%via CVEORG
CVE-2026-50527High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-47304High· 8.1
2mo ago

.NET Security Feature Bypass Vulnerability

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.22%via CVEORG
CVE-2026-50648High· 7.5
2mo ago

.NET Framework Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.84%via CVEORG
CVE-2026-50525High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 0.60%via CVEORG
CVE-2026-50659Medium· 6.5
2mo ago

.NET Spoofing Vulnerability

Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.55%via CVEORG
CVE-2026-47302High· 7.5
2mo ago

.NET Denial of Service Vulnerability

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.0%via CVEORG
CVE-2026-50653High· 7.5
2mo ago

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · Azure Active DirectoryEPSS 1.2%via NVD
CVE-2026-50652High· 7.5
2mo ago

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · Azure Active DirectoryEPSS 1.7%via NVD
.net_framework_3.5 vulnerabilities (CVEs) · VulnSea