Visual Studio
by Microsoft
CVEs (284)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69522 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69439 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-47303 | Hig | 0.57 | 8.8 | 0.01 | Jul 14, 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-47300 | Hig | 0.57 | 8.8 | 0.01 | Jul 14, 2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-41109 | Hig | 0.57 | 8.8 | 0.01 | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-21518 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-21256 | Hig | 0.57 | 8.8 | 0.01 | Feb 10, 2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-55319 | Hig | 0.57 | 8.8 | 0.01 | Sep 12, 2025 | Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-49739 | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2025 | Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2025-21178 | Hig | 0.57 | 8.8 | 0.02 | Jan 14, 2025 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2024-43488 | Hig | 0.57 | 8.8 | 0.01 | Oct 8, 2024 | Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. | ||
| CVE-2024-28938 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28937 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28936 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28935 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28934 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28933 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28932 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28931 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28930 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Visual Studio Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
Page 2 of 15