CVE-2025-55315
- EPSS 65.84%
- Veröffentlicht 14.10.2025 17:00:10
- Zuletzt bearbeitet 28.10.2025 21:15:37
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
CVE-2025-53773
- EPSS 2.57%
- Veröffentlicht 12.08.2025 17:09:51
- Zuletzt bearbeitet 15.08.2025 17:01:01
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-49739
- EPSS 0.8%
- Veröffentlicht 08.07.2025 16:58:15
- Zuletzt bearbeitet 16.07.2025 16:40:52
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-47959
- EPSS 7.15%
- Veröffentlicht 13.06.2025 01:10:44
- Zuletzt bearbeitet 10.07.2025 16:00:47
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
CVE-2025-30399
- EPSS 0.92%
- Veröffentlicht 13.06.2025 01:08:00
- Zuletzt bearbeitet 10.07.2025 14:25:37
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- EPSS 1.17%
- Veröffentlicht 13.05.2025 21:39:52
- Zuletzt bearbeitet 10.07.2025 14:54:17
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
CVE-2025-32702
- EPSS 0.62%
- Veröffentlicht 13.05.2025 16:59:11
- Zuletzt bearbeitet 19.05.2025 18:30:28
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-32703
- EPSS 0.46%
- Veröffentlicht 13.05.2025 16:58:50
- Zuletzt bearbeitet 19.05.2025 18:30:21
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
CVE-2025-26682
- EPSS 1.54%
- Veröffentlicht 08.04.2025 17:24:22
- Zuletzt bearbeitet 09.07.2025 16:32:39
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2025-29804
- EPSS 1.23%
- Veröffentlicht 08.04.2025 17:24:15
- Zuletzt bearbeitet 10.07.2025 15:16:56
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.