CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-70354HIGH | .NET Core Remote Code Execution Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/432 ## CVSS Details - **Versi… CWE-787Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.387% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-65810HIGH | .NET Framework Elevation of Privilege VulnerabilityRelative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. CWE-23Aug 11, 2026 | CVSS7.8v3.1 | EPSS0.351% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62872HIGH | .NET Framework Elevation of Privilege VulnerabilityIncorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. CWE-863Aug 11, 2026 | CVSS8.8v3.1 | EPSS0.538% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-62897HIGH | .NET Framework Remote Code Execution Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Windows Presentation Foundation. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An integer overflow or wraparound in .NET allows an unauthorized attacker to execute code locally. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/434 ## CVSS Details… CWE-190Aug 11, 2026 | CVSS7.0v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50659MEDIUM | Generated title:.NET SMTP Client Spoofing Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A spoofing vulnerability exists in the SMTP client implementation (System.Net.Mail) in .NET 8, .NET 9, and .NET 10, where an attacker can spoof messages during message routing. ## Announcement Announcement for this issue ca… CWE-116Jul 14, 2026 | CVSS6.5v3.1 | EPSS0.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50649HIGH | .NET Remote Code Execution VulnerabilityDeserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. CWE-502Jul 14, 2026 | CVSS7.8v3.1 | EPSS0.918% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50525HIGH | .NET Denial of Service Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability by supplying crafted encrypted XML … CWE-770Jul 14, 2026 | CVSS7.5v3.1 | EPSS0.604% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47304HIGH | .NET Security Feature Bypass Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A security feature bypass vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability to bypass encryption protecti… | CVSS8.1v3.1 | EPSS0.216% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50647HIGH | Active Directory Federation Server Denial of Service VulnerabilityLoop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. CWE-835Jul 14, 2026 | CVSS7.5v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50411HIGH | Windows Active Directory Federation Services Denial of Service VulnerabilityStack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. CWE-121Jul 14, 2026 | CVSS7.5v3.1 | EPSS0.78% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50355HIGH | Windows Active Directory Federation Services Denial of Service VulnerabilityStack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. CWE-121Jul 14, 2026 | CVSS7.5v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50324MEDIUM | Windows Active Directory Federation Services Denial of Service VulnerabilityLoop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. CWE-835Jul 14, 2026 | CVSS5.9v3.1 | EPSS0.782% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50368HIGH | Windows Active Directory Federation Services Denial of Service VulnerabilityStack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. CWE-121Jul 14, 2026 | CVSS7.5v3.1 | EPSS0.78% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50304HIGH | Windows Active Directory Federation Services Denial of Service VulnerabilityStack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. CWE-121Jul 14, 2026 | CVSS7.5v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50653HIGH | Azure Active Directory Denial of Service VulnerabilityLoop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | CVSS7.5v3.1 | EPSS0.78% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50652HIGH | Azure Active Directory Denial of Service VulnerabilityDeserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. CWE-502Jul 14, 2026 | CVSS7.5v3.1 | EPSS1.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32226MEDIUM | .NET Framework Denial of Service VulnerabilityConcurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network. CWE-362Apr 14, 2026 | CVSS5.9v3.1 | EPSS0.542% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41064MEDIUM | .NET Framework Information Disclosure VulnerabilityMicrosoft is releasing this security advisory to provide information about a vulnerability in .NET, .NET Core and .NET Framework's System.Data.SqlClient and Microsoft.Data.SqlClient NuGet Packages. A vulnerability exists in System.Data.SqlClient and Microsoft.Data.SqlClient libraries where a timeout occurring under high load can cause incorrect data to be returned as the result of an asynchronously executed query. ## <a name="mitigation-factors"></a>Mitigation factors If you are not talking t… Nov 9, 2022 | CVSS5.8v3.1 | EPSS0.747% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26929HIGH | .NET Framework Remote Code Execution Vulnerability.NET Framework Remote Code Execution Vulnerability. Sep 13, 2022 | CVSS7.8v3.1 | EPSS1.36% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |