CVE-2026-48027
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available…
All CVEs associated with "Microsoft Visual Studio". Page 1/3 • 299 CVEs.
A curated feed of “Microsoft Visual Studio”-related CVEs appears below. We currently track 299 CVEs for this tag (all time). In the last 365 days, 35 were published. Average CVSS is 7.4 (all time; 7.1 over 365d), and 75% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection'), CWE-20 - Improper Input Validation, CWE-94 - Improper Control of Generation of Code ('Code Injection').
In our taxonomy this topic maps to a LOW impact class. Developer and CI or CD tooling touches supply chains and secrets. Patch controllers and agents, enforce SSO or MFA, rotate tokens, isolate runners, and audit plugins. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | EOL | LTS |
|---|---|---|---|---|
| 18.6 | 18.6.2 | - | ||
| 18.5 | 18.5.3 | Expired | ||
| 18.4 | 18.4.4 | Expired | ||
| 18.3 | 18.3.3 | Expired | ||
| 18.2 | 18.2.2 | Expired | ||
| 18.1 | 18.1.1 | Expired | ||
| 18.0 | 18.0.2 | Expired | ||
| 17.14 | 17.14.32 | LTS | ||
| 17.13 | 17.13.7 | Expired | ||
| 17.12 | 17.12.20 | Soon | LTS | |
| 17.11 | 17.11.6 | Expired | ||
| 17.10 | 17.10.21 | Expired | LTS | |
| 17.9 | 17.9.7 | Expired | ||
| 17.8 | 17.8.23 | Expired | LTS | |
| 17.7 | 17.7.7 | Expired | ||
| 17.6 | 17.6.22 | Expired | LTS | |
| 17.5 | 17.5.5 | Expired | ||
| 17.4 | 17.4.21 | Expired | LTS | |
| 17.3 | 17.3.7 | Expired | ||
| 17.2 | 17.2.23 | Expired | LTS | |
| 17.1 | 17.1.7 | Expired | ||
| 17.0 | 17.0.23 | Expired | LTS | |
| 16.11 | 16.11.56 | |||
| 16.10 | 16.10.4 | Expired | ||
| 16.9 | 16.9.26 | Expired | ||
| 16.8 | 16.8.7 | Expired | ||
| 16.7 | 16.7.28 | Expired | ||
| 16.6 | 16.6.5 | Expired | ||
| 16.5 | 16.5.5 | Expired | ||
| 16.4 | 16.4.27 | Expired | ||
| 16.3 | 16.3.10 | Expired | ||
| 16.2 | 16.2.5 | Expired | ||
| 16.1 | 16.1.6 | Expired | ||
| 16.0 | 16.0.22 | Expired | ||
| 15.9 | 15.9.79 | |||
| 15.8 | 15.8.9 | Expired | ||
| 15.7 | 15.7.6 | Expired | ||
| 15.6 | 15.6.7 | Expired | ||
| 15.5 | 15.5.7 | Expired | ||
| 15.4 | 15.4.5 | Expired | ||
| 15.3 | 15.3.5 | Expired | ||
| 15.2 | 15.2.6 | Expired | ||
| 15.1 | 15.1.2 | Expired | ||
| 15.0 | 15.0.28 | Expired | ||
| 14.0 | Update 3 + KB3165756 | Expired | ||
| 12.0 | Update 5 | Expired | ||
| 11.0 | Update 4 | Expired | ||
| 10.0 | Service Pack 1 | Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Microsoft Visual Studio” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available…
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature ove…
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.
Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover/unicode-input-component are vulnerable to an XSS exploit in 0.1.9 of the packa…
An issue in Visual Studio Code Extensions Live Server v5.7.9 allows attackers to exfiltrate files via user interaction with a crafted HTML page.
An issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a crafted .Md file.
An issue in the code-runner.executorMap setting of Visual Studio Code Extensions Code Runner v0.12.2 allows attackers to execute arbitrary code when opening a crafted workspace.
Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a networ…
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Mon…
To prevent unexpected untrusted code execution, the Visual Studio Code Go extension is now disabled in Restricted Mode.
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-site scripting (XSS) vulnerability in the WebInteropApp/WebAppInterop, potential…
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspaces allow users to op…
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the V…
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Trust boundary violation in Visual Studio Code - Python extension allows an unauthorized attacker to execute code locally.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally.
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Uncontrolled search path element in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Installer Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Visual Studio Code Python Extension Remote Code Execution Vulnerability
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Visual Studio Collector Service Denial of Service Vulnerability
Visual Studio Code for Linux Remote Code Execution Vulnerability
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.
.NET and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are vulnerable to local command injection if the user…
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Information Disclosure Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
A vulnerability has been identified in SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2). Affected applications do not properly restrict the .NET BinaryFormatter when deserializing user-control…
A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 7), SIMATIC STEP 7 Safety V18 (All versions < V18…
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions < V18 Update 2). Aff…
Visual Studio Remote Code Execution Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authe…
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Visual Studio Code Elevation of Privilege Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
Visual Studio Elevation of Privilege Vulnerability
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
Visual Studio Code Python Extension Remote Code Execution Vulnerability
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes workspace trust component.
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Visual Studio Denial of Service Vulnerability
Visual Studio Code Jupyter Extension Spoofing Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
Visual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Visual Studio Remote Code Execution Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Visual Studio Code Remote Code Execution Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
.NET Core and Visual Studio Denial of Service Vulnerability
Visual Studio Tools for Office Runtime Spoofing Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
Visual Studio Code GitHub Pull Requests and Issues Extension Remote Code Execution Vulnerability
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
Visual Studio Code Spoofing Vulnerability
Visual Studio Information Disclosure Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
Visual Studio Code Spoofing Vulnerability
Visual Studio Spoofing Vulnerability