« Volver al listado

Microsoft

Microsoft .net: vulnerabilidades y CVE

Microsoft .net tiene 123 vulnerabilidades publicadas, 49 de ellas en los últimos 12 meses. 6 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE123
Últimos 12 meses49
Críticas6
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-44487Alta (7.5)100%⚠ Explotación activa10 oct 2023
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-38180Alta (7.5)14%⚠ Explotación activa8 ago 2023
.NET and Visual Studio Denial of Service Vulnerability

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-71328Alta (8.8)0.76%—8 sept 2026
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69806Alta (7)0.76%—8 sept 2026
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-69439Alta (8.8)0.84%—8 sept 2026
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69304Media (5.9)0.88%—8 sept 2026
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-70354Alta (7.8)0.36%—11 ago 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62909Alta (7.8)0.26%—11 ago 2026
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62902Media (6.5)0.87%—11 ago 2026
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901Alta (7.5)1.2%—11 ago 2026
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62900Media (5.9)0.75%—11 ago 2026
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899Media (5.9)0.75%—11 ago 2026
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62898Alta (7.5)1.0%—11 ago 2026
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62897Alta (7)0.37%—11 ago 2026
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62886Alta (7.8)0.47%—11 ago 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62871Alta (7.8)0.47%—11 ago 2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-58641Alta (7.8)0.47%—11 ago 2026
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50659Media (6.5)0.74%—14 jul 2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-50651Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50650Alta (7.8)0.46%—14 jul 2026
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50649Alta (7.8)4.0%—14 jul 2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-50648Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50646Alta (7.8)4.0%—14 jul 2026
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50528Alta (8.2)0.61%—14 jul 2026
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50527Alta (7.5)1.2%—14 jul 2026
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50526Media (5.5)0.22%—14 jul 2026
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-50525Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50524Alta (7.5)1.2%—14 jul 2026
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47304Crítica (9.8)0.29%—14 jul 2026
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-47303Alta (8.8)0.84%—14 jul 2026
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47302Alta (7.5)1.2%—14 jul 2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47300Alta (8.8)0.78%—14 jul 2026
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application2
  2. T1499.004 Application or System Exploitation2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft