CVE-2026-78461
- EPSS 1.06%
- Veröffentlicht 08.09.2026 17:13:37
- Zuletzt bearbeitet 11.09.2026 21:11:21
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-70334
- EPSS 0.44%
- Veröffentlicht 08.09.2026 17:12:17
- Zuletzt bearbeitet 11.09.2026 21:11:42
Incomplete list of disallowed inputs in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-69522
- EPSS 0.81%
- Veröffentlicht 08.09.2026 17:10:32
- Zuletzt bearbeitet 29.09.2026 22:17:46
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-70354
- EPSS 0.29%
- Veröffentlicht 11.08.2026 17:07:15
- Zuletzt bearbeitet 17.08.2026 12:56:51
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-70335
- EPSS 0.47%
- Veröffentlicht 11.08.2026 17:05:32
- Zuletzt bearbeitet 25.09.2026 20:17:45
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVE-2026-70336
- EPSS 0.59%
- Veröffentlicht 11.08.2026 17:05:32
- Zuletzt bearbeitet 25.09.2026 20:17:45
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-69306
- EPSS 0.4%
- Veröffentlicht 11.08.2026 17:05:18
- Zuletzt bearbeitet 25.09.2026 20:17:42
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-69278
- EPSS 0.33%
- Veröffentlicht 11.08.2026 17:05:17
- Zuletzt bearbeitet 25.09.2026 20:17:42
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-69320
- EPSS 0.46%
- Veröffentlicht 11.08.2026 17:05:17
- Zuletzt bearbeitet 25.09.2026 20:17:42
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-47285
- EPSS 0.87%
- Veröffentlicht 11.08.2026 17:03:41
- Zuletzt bearbeitet 25.09.2026 20:17:06
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.