Vulnerabilities (CVE)

Filtered by vendor Microsoft
Filtered by product Visual Studio 2022
Angry Yack Logo
Total 118 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-21256 1 Microsoft 1 Visual Studio 2022 2026-02-11 N/A 8.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-21257 1 Microsoft 1 Visual Studio 2022 2026-02-11 N/A 8.0 HIGH
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network.
CVE-2025-62214 1 Microsoft 1 Visual Studio 2022 2025-11-17 N/A 6.7 MEDIUM
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally.
CVE-2023-44487 32 Akka, Amazon, Apache and 29 more 313 Http Server, Opensearch Data Prepper, Apisix and 310 more 2025-11-07 N/A 7.5 HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2025-55315 1 Microsoft 2 Asp.net Core, Visual Studio 2022 2025-10-28 N/A 9.9 CRITICAL
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
CVE-2023-38180 2 Fedoraproject, Microsoft 4 Fedora, .net, Asp.net Core and 1 more 2025-10-28 N/A 7.5 HIGH
.NET and Visual Studio Denial of Service Vulnerability
CVE-2025-55248 3 Apple, Linux, Microsoft 20 Macos, Linux Kernel, .net and 17 more 2025-10-23 N/A 4.8 MEDIUM
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
CVE-2025-55240 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2025-10-17 N/A 7.3 HIGH
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-53773 1 Microsoft 1 Visual Studio 2022 2025-08-15 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-49739 1 Microsoft 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more 2025-07-16 N/A 8.8 HIGH
Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-47959 1 Microsoft 1 Visual Studio 2022 2025-07-10 N/A 7.1 HIGH
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.
CVE-2025-29804 1 Microsoft 1 Visual Studio 2022 2025-07-10 N/A 7.3 HIGH
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-29802 1 Microsoft 1 Visual Studio 2022 2025-07-10 N/A 7.3 HIGH
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-26646 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2025-07-10 N/A 8.0 HIGH
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
CVE-2025-21171 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2025-07-10 N/A 7.5 HIGH
.NET Remote Code Execution Vulnerability
CVE-2025-30399 3 Apple, Linux, Microsoft 6 Macos, Linux Kernel, .net and 3 more 2025-07-10 N/A 7.5 HIGH
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2025-26682 1 Microsoft 2 Asp.net Core, Visual Studio 2022 2025-07-09 N/A 7.5 HIGH
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2025-24070 1 Microsoft 2 Asp.net Core, Visual Studio 2022 2025-07-02 N/A 7.0 HIGH
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-24998 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2025-07-01 N/A 7.3 HIGH
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-25003 1 Microsoft 2 Visual Studio 2019, Visual Studio 2022 2025-07-01 N/A 7.3 HIGH
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2022-35777 1 Microsoft 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more 2025-05-29 N/A 8.8 HIGH
Visual Studio Remote Code Execution Vulnerability
CVE-2025-32702 1 Microsoft 2 Visual Studio 2019, Visual Studio 2022 2025-05-19 N/A 7.8 HIGH
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2025-32703 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2025-05-19 N/A 5.5 MEDIUM
Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.
CVE-2025-21173 2 Linux, Microsoft 3 Linux Kernel, .net, Visual Studio 2022 2025-05-06 N/A 7.3 HIGH
.NET Elevation of Privilege Vulnerability
CVE-2024-38229 3 Apple, Linux, Microsoft 5 Macos, Linux Kernel, .net and 2 more 2025-05-06 N/A 8.1 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-35264 1 Microsoft 2 .net, Visual Studio 2022 2025-05-06 N/A 8.1 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2025-21172 3 Apple, Linux, Microsoft 7 Macos, Linux Kernel, .net and 4 more 2025-05-06 N/A 7.5 HIGH
.NET and Visual Studio Remote Code Execution Vulnerability
CVE-2024-43484 3 Apple, Linux, Microsoft 21 Macos, Linux Kernel, .net and 18 more 2025-03-28 N/A 7.5 HIGH
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
CVE-2022-41032 2 Fedoraproject, Microsoft 5 Fedora, .net, .net Core and 2 more 2025-02-28 N/A 7.8 HIGH
NuGet Client Elevation of Privilege Vulnerability
CVE-2022-30184 3 Apple, Fedoraproject, Microsoft 7 Macos, Fedora, .net and 4 more 2025-02-28 4.3 MEDIUM 5.5 MEDIUM
.NET and Visual Studio Information Disclosure Vulnerability
CVE-2025-21206 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2025-02-28 N/A 7.3 HIGH
Visual Studio Installer Elevation of Privilege Vulnerability
CVE-2025-21178 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2025-01-27 N/A 8.8 HIGH
Visual Studio Remote Code Execution Vulnerability
CVE-2024-21409 1 Microsoft 16 .net, .net Framework, Powershell and 13 more 2025-01-17 N/A 7.3 HIGH
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
CVE-2025-21405 1 Microsoft 1 Visual Studio 2022 2025-01-17 N/A 7.3 HIGH
Visual Studio Elevation of Privilege Vulnerability
CVE-2024-28931 1 Microsoft 5 Odbc Driver For Sql Server, Sql Server 2019, Sql Server 2022 and 2 more 2025-01-14 N/A 8.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28938 1 Microsoft 5 Odbc Driver For Sql Server, Sql Server 2019, Sql Server 2022 and 2 more 2025-01-14 N/A 8.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28937 1 Microsoft 5 Odbc Driver For Sql Server, Sql Server 2019, Sql Server 2022 and 2 more 2025-01-14 N/A 8.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28936 1 Microsoft 5 Odbc Driver For Sql Server, Sql Server 2019, Sql Server 2022 and 2 more 2025-01-14 N/A 8.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28935 1 Microsoft 5 Odbc Driver For Sql Server, Sql Server 2019, Sql Server 2022 and 2 more 2025-01-14 N/A 8.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
CVE-2024-28934 1 Microsoft 5 Odbc Driver For Sql Server, Sql Server 2019, Sql Server 2022 and 2 more 2025-01-14 N/A 8.8 HIGH
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability