CVE Vulnerabilities for "product:visual_studio_2022"

Showing 1-10 of 115 CVEs (filtered from 316,527 total)

Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

CRITICAL 9.9
EPSS 0.1%
10/14/2025
2025

Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.

MEDIUM 4.8
EPSS 0.0%
10/14/2025
2025

Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.

HIGH 7.3
EPSS 0.0%
10/14/2025
2025

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

HIGH 7.8
EPSS 0.5%
1 exploit
8/12/2025
2025

Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.

HIGH 8.8
EPSS 0.1%
7/8/2025
2025

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network.

HIGH 7.1
EPSS 0.1%
6/13/2025
2025

Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.

HIGH 7.5
EPSS 0.1%
6/13/2025
2025

External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.

HIGH 8
EPSS 0.0%
5/13/2025
2025

Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally.

MEDIUM 5.5
EPSS 0.1%
5/13/2025
2025

Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

HIGH 7.8
EPSS 0.1%
5/13/2025
2025
Page 1 of 2