CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

.net_core

32 known vulnerabilities · sorted by CVSS score

CVE-2020-0606
HIGH8.8

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0605.

microsoft / .net_framework+22
Network
Published Jan 14, 2020
Page 1 of 2
CVE-2020-0605
HIGH8.8

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0606.

microsoft / .net_framework+27
Network
Published Jan 14, 2020
CVE-2021-26701
HIGH8.1

.NET Core Remote Code Execution Vulnerability

microsoft / .net+9
Network
Published Feb 25, 2021
CVE-2021-24112
HIGH8.1

.NET Core Remote Code Execution Vulnerability

microsoft / .net+4
Network
Published Feb 25, 2021
CVE-2020-1147
HIGH7.8

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.

microsoft / .net_core+40
Local
Published Jul 14, 2020
CVE-2022-41032
HIGH7.8

NuGet Client Elevation of Privilege Vulnerability

microsoft / .net+10
Local
Published Oct 11, 2022
CVE-2018-0786
HIGH7.5

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, 4.7, 4.7.1, .NET Core 1.0 and 2.0, and PowerShell Core 6.0.0 allow a security feature bypass vulnerability due to the way certificates are validated, aka ".NET Security Feature Bypass Vulnerability."

microsoft / .net_core+17
Network
Published Jan 10, 2018
CVE-2019-0981
HIGH7.5

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.

microsoft / .net_core+27
Network
Published May 16, 2019
CVE-2021-26423
HIGH7.5

.NET Core and Visual Studio Denial of Service Vulnerability

microsoft / .net+7
Network
Published Aug 12, 2021
CVE-2022-29145
HIGH7.5

.NET and Visual Studio Denial of Service Vulnerability

microsoft / .net+8
Network
Published May 10, 2022
CVE-2018-0765
HIGH7.5

A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.7.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.7/4.7.1, Microsoft .NET Framework 4.6, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6.2/4.7/4.7.1, .NET Core 2.0, Microsoft .NET Framework 4.7.2.

microsoft / .net_core+21
Network
Published May 9, 2018
CVE-2019-1301
HIGH7.5

A denial of service vulnerability exists when .NET Core improperly handles web requests, aka '.NET Core Denial of Service Vulnerability'.

microsoft / .net_core+3
Network
Published Sep 11, 2019
CVE-2019-0545
HIGH7.5

An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.

microsoft / .net_framework+22
Network
Published Jan 8, 2019
CVE-2022-23267
HIGH7.5

.NET and Visual Studio Denial of Service Vulnerability

microsoft / .net+11
Network
Published May 10, 2022
CVE-2018-0764
HIGH7.5

Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.

microsoft / .net_core+18
Network
Published Jan 10, 2018
CVE-2019-0980
HIGH7.5

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.

microsoft / .net_core+27
Network
Published May 16, 2019
CVE-2022-29117
HIGH7.5

.NET and Visual Studio Denial of Service Vulnerability

microsoft / .net+8
Network
Published May 10, 2022
CVE-2019-0820
HIGH7.5

A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.

microsoft / .net_core+38
Network
Published May 16, 2019
CVE-2020-1108
HIGH7.5

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

microsoft / .net+96
Network
Published May 21, 2020
CVE-2022-38013
HIGH7.5

.NET Core and Visual Studio Denial of Service Vulnerability

microsoft / .net+10
Network
Published Sep 13, 2022