CVE-2026-50520
- EPSS 0.25%
- Veröffentlicht 14.07.2026 17:05:07
- Zuletzt bearbeitet 16.07.2026 15:02:15
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVE-2026-47282
- EPSS 0.61%
- Veröffentlicht 14.07.2026 17:04:39
- Zuletzt bearbeitet 16.07.2026 17:21:30
Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-45496
- EPSS 0.36%
- Veröffentlicht 14.07.2026 17:04:39
- Zuletzt bearbeitet 16.07.2026 17:30:48
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-48569
- EPSS 0.35%
- Veröffentlicht 09.06.2026 17:17:45
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-47292
- EPSS 0.44%
- Veröffentlicht 09.06.2026 17:17:34
- Zuletzt bearbeitet 24.08.2026 16:17:12
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVE-2026-47287
- EPSS 0.79%
- Veröffentlicht 09.06.2026 17:17:34
- Zuletzt bearbeitet 23.07.2026 08:10:00
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVE-2026-47284
- EPSS 0.92%
- Veröffentlicht 09.06.2026 17:17:34
- Zuletzt bearbeitet 23.07.2026 08:10:00
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-47281
- EPSS 0.76%
- Veröffentlicht 09.06.2026 17:17:33
- Zuletzt bearbeitet 23.07.2026 08:10:00
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-45482
- EPSS 0.35%
- Veröffentlicht 09.06.2026 17:17:22
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-40376
- EPSS 0.67%
- Veröffentlicht 09.06.2026 17:17:06
- Zuletzt bearbeitet 23.07.2026 08:10:00
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.