Visual Studio Code Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Release Notes
Browse 4,355 advisories from this official source. Search by product, CVE, severity, or advisory ID.
Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Release Notes
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Release Notes
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Release Notes
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Release Notes
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Release Notes
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Release Notes
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Release Notes
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Release Notes
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Mariner
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120233. Install KB5120228. Install KB5120418. Install KB5120386. Install KB5120385.
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Install KB5120238. Install KB5120242. Install KB5120229. Install KB5120249. Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5120240. Install KB5121000. Install KB5120418. Install ...
Out-of-bounds read in Windows TCP/IP allows an authorized attacker to disclose information locally.
Install KB5099538. Install KB5099540. Install KB5099539. Install KB5099536. Install KB5101650. Install KB5101649. Install KB5099535. Install KB5099445. Install KB5099444.
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Install KB5120233. Install KB5120228. Install KB5121003. Install KB5120994. Install KB5121000.
We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.
Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.
Read how SecurityAlert collects and checks threat intelligence.