Microsoft

Visual Studio

111 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.69%
  • Veröffentlicht 11.08.2026 17:03:40
  • Zuletzt bearbeitet 24.09.2026 14:17:35

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 11.08.2026 17:03:24
  • Zuletzt bearbeitet 25.09.2026 20:17:09

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

  • EPSS 0.77%
  • Veröffentlicht 14.07.2026 17:09:38
  • Zuletzt bearbeitet 16.07.2026 15:34:36

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

  • EPSS 0.44%
  • Veröffentlicht 14.07.2026 17:09:37
  • Zuletzt bearbeitet 16.07.2026 15:42:04

Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 14.07.2026 17:05:07
  • Zuletzt bearbeitet 16.07.2026 15:02:15

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 14.07.2026 17:04:39
  • Zuletzt bearbeitet 16.07.2026 17:30:48

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Medienbericht
  • EPSS 0.61%
  • Veröffentlicht 14.07.2026 17:04:39
  • Zuletzt bearbeitet 16.07.2026 17:21:30

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

  • EPSS 0.29%
  • Veröffentlicht 29.06.2026 12:33:52
  • Zuletzt bearbeitet 15.07.2026 02:18:11

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user ...

  • EPSS 0.51%
  • Veröffentlicht 19.06.2026 20:28:35
  • Zuletzt bearbeitet 17.08.2026 15:13:41

Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Medienbericht
  • EPSS 0.35%
  • Veröffentlicht 09.06.2026 17:17:45
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.