Visual Studio Code
Vendor:
First CVE: Jun 26, 2018 · Active for 8 years
68
Total CVEs
More Total CVEs than 98% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 61% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Visual Studio Code over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
CVE Severity & Scoring
Visual Studio Code68 CVEs
18%
78%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local47 (69.1%)
Network21 (30.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low66 (97.1%)
High2 (2.9%)
Unknown0 (0.0%)
User Interaction
None11 (16.2%)
Unknown0 (0.0%)
Required57 (83.8%)
Privileges Required
Low15 (22.1%)
High0 (0.0%)
None53 (77.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (68 CVEs).
68 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41034HIGH Visual Studio Code Remote Code Execution Vulnerability | Oct 11, 2022 | 7.8 | 73 | NO | YES |
CVE-2022-30129HIGH Visual Studio Code Remote Code Execution Vulnerability | May 10, 2022 | 8.8 | 51 | NO | NO |
CVE-2026-47281CRITICAL Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | Jun 9, 2026 | 9.6 | 40 | NO | NO |
CVE-2019-0728HIGH A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vuln | Mar 5, 2019 | 7.8 | 40 | NO | NO |
CVE-2026-57102HIGH Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | Jul 14, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-41613HIGH Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | May 12, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-41109HIGH Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a s | May 12, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-50520HIGH Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. | Jul 14, 2026 | 8.4 | 34 | NO | NO |
CVE-2025-55319CRITICAL Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network. | Sep 12, 2025 | 9.8 | 34 | NO | NO |
CVE-2021-43891HIGH Visual Studio Code Remote Code Execution Vulnerability | Dec 15, 2021 | 7.8 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (68 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (68 CVEs).
Media Mentions
Signals from CVEs in this product scope (68 CVEs).
Top CNAs Publishing CVEs For Visual Studio Code
Top CWEs
Versions
No cataloged versions.