CVE-2026-45591
- EPSS 2.43%
- Veröffentlicht 09.06.2026 17:17:26
- Zuletzt bearbeitet 23.07.2026 08:10:00
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-40376
- EPSS 0.67%
- Veröffentlicht 09.06.2026 17:17:06
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41613
- EPSS 0.52%
- Veröffentlicht 12.05.2026 16:59:32
- Zuletzt bearbeitet 15.05.2026 14:23:50
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-41611
- EPSS 0.42%
- Veröffentlicht 12.05.2026 16:58:56
- Zuletzt bearbeitet 15.05.2026 15:05:19
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
- EPSS 0.6%
- Veröffentlicht 12.05.2026 16:58:55
- Zuletzt bearbeitet 15.05.2026 15:11:18
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-41109
- EPSS 0.86%
- Veröffentlicht 12.05.2026 16:58:55
- Zuletzt bearbeitet 10.08.2026 18:17:46
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-32203
- EPSS 1.9%
- Veröffentlicht 14.04.2026 16:58:38
- Zuletzt bearbeitet 15.07.2026 02:19:53
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
CVE-2026-32178
- EPSS 2.28%
- Veröffentlicht 14.04.2026 16:57:31
- Zuletzt bearbeitet 15.07.2026 02:19:53
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
- EPSS 0.79%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 11.02.2026 21:41:36
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CVE-2026-21518
- EPSS 1.36%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 23.02.2026 17:23:27
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.