Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.44% | — | Microsoft VscodeAIOvsxAI | 14/9/2026 | 16/9/2026 | Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}/{path}, WebResourceService opened the entry with ZipFile.getInputStream() and passed… | |
| Aplazada | Alta (7.8) | 0.19% | — | Streetsidesoftware Vscode-spell-checkerAI | 9/2/2026 | 17/6/2026 | vscode-spell-checker is a basic spell checker that works well with code and documents. Prior to v4.5.4, DocumentSettings._determineIsTrusted treats the configuration value cSpell.trustedWorkspace as the authoritative trust flag. The value defaults to true (package.json) and is read from workspace configuration each… | |
| Aplazada | Media (6.8) | 0.59% | — | Microsoft VscodeAIVmware CLIAI | 14/1/2026 | 17/6/2026 | The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine. | |
| Aplazada | Alta (8.8) | 0.34% | — | Anthropic Claude CodeAIMicrosoft VscodeAIJetbrains IntellijAIJetbrains PycharmAI+1 | 24/6/2025 | 17/6/2026 | Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor, Windsurf, and VSCodium) and JetBrains IDEs (e.g., IntelliJ, Pycharm, and Android Studio) are vulnerable to unauthorized websocket connections from an attacker when visiting attacker-controlled webpages. Claude Code for… | |
| Aplazada | Media (4.8) | 0.23% | — | Thautwarm Vscode-dianaAIPalletsprojects JinjaAI | 19/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (8.1) | 0.54% | — | Cognition DevinAIMicrosoft VscodeAI | 16/12/2024 | 17/6/2026 | Cognition Devin before 2024-12-12 provides write access to code by an attacker who discovers the https://vscode-randomly_generated_string.devinapps.com URL (aka the VSCode live share URL) for a specific "Use Devin's Machine" session. For example, this URL may be discovered if a customer posts a screenshot of a Devin… | |
| Modificada | Crítica (9.1) | 1.3% | — | Redhat Vscode-xml | 18/2/2022 | 17/6/2026 | A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file. | |
| Modificada | Crítica (9.8) | 3.0% | — | Vscode-phpmd Project Vscode-phpmd | 30/7/2021 | 17/6/2026 | The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attackers to execute arbitrary code via a crafted phpmd.command value in a workspace folder. | |
| Modificada | Alta (7.8) | 62% | — | Microsoft Vscode-maven | 13/4/2021 | 17/6/2026 | Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Gitlab-vscode-extension | 1/4/2021 | 17/6/2026 | Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system | |
| Modificada | Alta (8.8) | 1.2% | — | Vscode-rufo Project Vscode-rufo | 31/3/2021 | 17/6/2026 | The unofficial vscode-rufo extension before 0.0.4 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted workspace folder. | |
| Modificada | Alta (8.6) | 1.2% | — | Gitlab-vscode-extension | 22/6/2020 | 17/6/2026 | Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system |