Microsoft
Microsoft .net: vulnerabilidades y CVE
Microsoft .net tiene 123 vulnerabilidades publicadas, 49 de ellas en los últimos 12 meses. 6 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE123
Últimos 12 meses49
Críticas6
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-38180 | Alta (7.5) | 14% | ⚠ Explotación activa | 8 ago 2023 | .NET and Visual Studio Denial of Service Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-71328 | Alta (8.8) | 0.76% | — | 8 sept 2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. |
| CVE-2026-69806 | Alta (7) | 0.76% | — | 8 sept 2026 | Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-69439 | Alta (8.8) | 0.84% | — | 8 sept 2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69304 | Media (5.9) | 0.88% | — | 8 sept 2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. |
| CVE-2026-70354 | Alta (7.8) | 0.36% | — | 11 ago 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-62909 | Alta (7.8) | 0.26% | — | 11 ago 2026 | Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. |
| CVE-2026-62902 | Media (6.5) | 0.87% | — | 11 ago 2026 | Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62901 | Alta (7.5) | 1.2% | — | 11 ago 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-62900 | Media (5.9) | 0.75% | — | 11 ago 2026 | Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62899 | Media (5.9) | 0.75% | — | 11 ago 2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-62898 | Alta (7.5) | 1.0% | — | 11 ago 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-62897 | Alta (7) | 0.37% | — | 11 ago 2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-62886 | Alta (7.8) | 0.47% | — | 11 ago 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-62871 | Alta (7.8) | 0.47% | — | 11 ago 2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-58641 | Alta (7.8) | 0.47% | — | 11 ago 2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-50659 | Media (6.5) | 0.74% | — | 14 jul 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-50651 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50650 | Alta (7.8) | 0.46% | — | 14 jul 2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. |
| CVE-2026-50649 | Alta (7.8) | 4.0% | — | 14 jul 2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. |
| CVE-2026-50648 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50646 | Alta (7.8) | 4.0% | — | 14 jul 2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. |
| CVE-2026-50528 | Alta (8.2) | 0.61% | — | 14 jul 2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-50527 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50526 | Media (5.5) | 0.22% | — | 14 jul 2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. |
| CVE-2026-50525 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-50524 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47304 | Crítica (9.8) | 0.29% | — | 14 jul 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. |
| CVE-2026-47303 | Alta (8.8) | 0.84% | — | 14 jul 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-47302 | Alta (7.5) | 1.2% | — | 14 jul 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. |
| CVE-2026-47300 | Alta (8.8) | 0.78% | — | 14 jul 2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.