Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3070▲ 562 respecto a la semana anterior
Críticas / altas1457▲ 278 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.64%—Microsoft Github Copilot Chat11/8/202624/9/2026
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Github Copilot14/7/202622/7/2026
Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.5)1.2%—Microsoft Github Copilot22/6/202630/6/2026
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.
AnalizadaAlta (7.5)0.92%—Microsoft Github Copilot Chat19/6/202617/8/2026
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.74%—Microsoft Github Copilot Chat14/4/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.8)0.84%—Microsoft Github Copilot10/2/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Github Copilot9/12/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.8)0.47%—Microsoft Github Copilot Chat11/11/202517/6/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (8.8)0.75%—Microsoft Github Copilot Chat11/11/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.
AplazadaMedia (5.1)0.10%—Obsidian Github Copilot PluginAI5/9/202517/6/2026
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.