CVE-2026-32178
- EPSS 2.28%
- Veröffentlicht 14.04.2026 16:57:31
- Zuletzt bearbeitet 15.07.2026 02:19:53
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-21518
- EPSS 1.36%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 23.02.2026 17:23:27
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- EPSS 0.79%
- Veröffentlicht 10.02.2026 18:16:34
- Zuletzt bearbeitet 11.02.2026 21:41:36
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
CVE-2026-21256
- EPSS 1.1%
- Veröffentlicht 10.02.2026 18:16:27
- Zuletzt bearbeitet 11.02.2026 21:37:01
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
- EPSS 0.85%
- Veröffentlicht 10.02.2026 18:16:27
- Zuletzt bearbeitet 11.02.2026 19:47:12
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
- EPSS 0.56%
- Veröffentlicht 20.11.2025 22:18:57
- Zuletzt bearbeitet 26.11.2025 00:15:50
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
- EPSS 0.42%
- Veröffentlicht 11.11.2025 18:15:50
- Zuletzt bearbeitet 14.11.2025 15:30:40
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
CVE-2025-55315
- EPSS 65.84%
- Veröffentlicht 14.10.2025 17:00:10
- Zuletzt bearbeitet 28.10.2025 21:15:37
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
CVE-2025-55319
- EPSS 0.91%
- Veröffentlicht 12.09.2025 00:49:27
- Zuletzt bearbeitet 20.02.2026 17:25:39
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2025-49739
- EPSS 0.8%
- Veröffentlicht 08.07.2025 16:58:15
- Zuletzt bearbeitet 16.07.2025 16:40:52
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.