Visual Studio
by Microsoft
CVEs (284)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36759 | Med | 0.44 | 6.7 | 0.01 | Sep 12, 2023 | Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-41032 | Hig | 0.44 | 7.8 | 0.01 | Oct 11, 2022 | NuGet Client Elevation of Privilege Vulnerability | ||
| CVE-2023-36799 | Med | 0.43 | 6.5 | 0.05 | Sep 12, 2023 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-33144 | Med | 0.43 | 6.6 | 0.01 | Jun 14, 2023 | Visual Studio Code Spoofing Vulnerability | ||
| CVE-2023-29338 | Med | 0.43 | 6.6 | 0.01 | May 9, 2023 | Visual Studio Code Spoofing Vulnerability | ||
| CVE-2021-1721 | Med | 0.43 | 6.5 | 0.03 | Feb 25, 2021 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2020-1130 | Med | 0.43 | 6.6 | 0.01 | Sep 11, 2020 | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this… | ||
| CVE-2019-1079 | Med | 0.43 | 6.5 | 0.05 | Jul 15, 2019 | An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'. | ||
| CVE-2026-62901 | Hig | 0.42 | 7.5 | 0.01 | Aug 11, 2026 | Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-62898 | Hig | 0.42 | 7.5 | 0.01 | Aug 11, 2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-50659 | Med | 0.42 | 6.5 | 0.01 | Jul 14, 2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-32203 | Hig | 0.42 | 7.5 | 0.02 | Apr 14, 2026 | Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-32178 | Hig | 0.42 | 7.5 | 0.02 | Apr 14, 2026 | Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38167 | Med | 0.42 | 6.5 | 0.01 | Aug 13, 2024 | .NET and Visual Studio Information Disclosure Vulnerability | ||
| CVE-2024-21392 | Hig | 0.42 | 7.5 | 0.03 | Mar 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2023-32032 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2023 | .NET and Visual Studio Elevation of Privilege Vulnerability | ||
| CVE-2022-38013 | Hig | 0.42 | 7.5 | 0.04 | Sep 13, 2022 | .NET Core and Visual Studio Denial of Service Vulnerability | ||
| CVE-2022-23267 | Hig | 0.42 | 7.5 | 0.05 | May 10, 2022 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2019-1425 | Med | 0.42 | 6.5 | 0.03 | Nov 12, 2019 | An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'. | ||
| CVE-2019-0757 | Med | 0.42 | 6.5 | 0.03 | Apr 9, 2019 | A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'. |
- risk 0.44cvss 6.7epss 0.01
Visual Studio Elevation of Privilege Vulnerability
- risk 0.44cvss 7.8epss 0.01
NuGet Client Elevation of Privilege Vulnerability
- risk 0.43cvss 6.5epss 0.05
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.43cvss 6.6epss 0.01
Visual Studio Code Spoofing Vulnerability
- risk 0.43cvss 6.6epss 0.01
Visual Studio Code Spoofing Vulnerability
- risk 0.43cvss 6.5epss 0.03
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.43cvss 6.6epss 0.01
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could exploit this…
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when Visual Studio improperly parses XML input in certain settings files, aka 'Visual Studio Information Disclosure Vulnerability'.
- risk 0.42cvss 7.5epss 0.01
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 7.5epss 0.01
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 7.5epss 0.02
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 7.5epss 0.02
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
.NET and Visual Studio Information Disclosure Vulnerability
- risk 0.42cvss 7.5epss 0.03
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.01
.NET and Visual Studio Elevation of Privilege Vulnerability
- risk 0.42cvss 7.5epss 0.04
.NET Core and Visual Studio Denial of Service Vulnerability
- risk 0.42cvss 7.5epss 0.05
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.03
An elevation of privilege vulnerability exists when Visual Studio fails to properly validate hardlinks while extracting archived files, aka 'Visual Studio Elevation of Privilege Vulnerability'.
- risk 0.42cvss 6.5epss 0.03
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Page 11 of 15