Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.3)0.44%—Microsoft VscodeAIOvsxAI14/9/202616/9/2026
Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}/{path}, WebResourceService opened the entry with ZipFile.getInputStream() and passed…
AplazadaAlta (7.8)0.19%—Streetsidesoftware Vscode-spell-checkerAI9/2/202617/6/2026
vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each…
AplazadaMedia (6.8)0.59%—Microsoft VscodeAIVmware CLIAI14/1/202617/6/2026
The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.
AplazadaAlta (8.8)0.34%—Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+124/6/202517/6/2026
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for…
AplazadaMedia (4.8)0.23%—Thautwarm Vscode-dianaAIPalletsprojects JinjaAI19/4/202517/6/2026
A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
AplazadaAlta (8.1)0.54%—Cognition DevinAIMicrosoft VscodeAI16/12/202417/6/2026
Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin…
ModificadaCrítica (9.1)1.3%—Redhat Vscode-xml18/2/202217/6/2026
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
ModificadaCrítica (9.8)3.0%—Vscode-phpmd Project Vscode-phpmd30/7/202117/6/2026
The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder.
ModificadaAlta (7.8)62%—Microsoft Vscode-maven13/4/202117/6/2026
Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability
ModificadaAlta (7.8)1.1%—Gitlab-vscode-extension1/4/202117/6/2026
Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
ModificadaAlta (8.8)1.2%—Vscode-rufo Project Vscode-rufo31/3/202117/6/2026
The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder.
ModificadaAlta (8.6)1.2%—Gitlab-vscode-extension22/6/202017/6/2026
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system