Vulnerabilities
Vulnerable Software
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVSS Score
7.1
EPSS Score
0.003
Published
2026-06-09
Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVSS Score
6.5
EPSS Score
0.006
Published
2026-06-09
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVSS Score
6.5
EPSS Score
0.005
Published
2026-06-09
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-06-09
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.6
EPSS Score
0.004
Published
2026-06-09
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.006
Published
2026-06-09
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-05-12
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.8
EPSS Score
0.009
Published
2026-05-12
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVSS Score
6.3
EPSS Score
0.006
Published
2026-05-12
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-05-12


Contact Us

Shodan ® - All rights reserved