Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Media (6.1) | 0.48% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.4) | 0.35% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.5) | 0.87% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.47% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Pendiente de análisis | Media (4.4) | 0.33% | — | Github CLIAIGithub CodespaceAIMicrosoft Visual Studio CodeAI | 9/7/2026 | 14/7/2026 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS… | |
| Analizada | Media (5.5) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 9/6/2026 | 24/8/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.6) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (8.4) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.1) | 0.68% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Baja (3.3) | 0.50% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5) | 0.71% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 12/5/2026 | 10/8/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | |
| Aplazada | Crítica (10) | 0.45% | — | Microsoft Visual Studio CodeAIAquasec TrivyAI | 5/3/2026 | 17/6/2026 | Trivy Vulnerability Scanner is a VS Code extension that helps find vulnerabilities. In Trivy VSCode Extension version 1.8.12, which was distributed via OpenVSX marketplace was compromised and contained malicious code designed to leverage local AI coding agent to collect and exfiltrate sensitive information. Users… | |
| Analizada | Alta (8) | 0.82% | — | Microsoft Visual Studio Code | 10/2/2026 | 17/6/2026 | Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. | |
| Modificada | Alta (8.8) | 1.4% | — | Microsoft Visual Studio Code | 10/2/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Modificada | Alta (8) | 0.56% | — | Microsoft Visual Studio Code | 20/11/2025 | 17/6/2026 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5) | 0.42% | — | Microsoft Visual Studio Code | 11/11/2025 | 17/6/2026 | Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally. | |
| Aplazada | Media (6.6) | 0.35% | — | Minecraft Rcon TerminalAIMicrosoft Visual Studio CodeAI | 3/10/2025 | 17/6/2026 | Minecraft RCON Terminal is a VS Code extension that streamlines Minecraft server management. Versions 0.1.0 through 2.0.6 stores passwords using VS Code's configuration API which writes to settings.json in plaintext. This issue is fixed in version 2.1.0. | |
| Modificada | Crítica (9.8) | 0.92% | — | Microsoft Visual Studio Code | 12/9/2025 | 17/6/2026 | Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (5.1) | 0.21% | — | Amazon Q DeveloperAIMicrosoft Visual Studio CodeAI | 30/7/2025 | 17/6/2026 | The Amazon Q Developer Visual Studio Code (VS Code) extension v1.84.0 contains inert, injected code designed to call the Q Developer CLI. The code executes when the extension is launched within the VS Code environment; however the injected code contains a syntax error which prevents it from making a successful API… |