Visual Studio Code

Vendor:

First CVE: Jun 26, 2018 · Active for 8 years

68
Total CVEs
More Total CVEs than 98% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 61% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Visual Studio Code over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 26, 2018
8 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Visual Studio Code68 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local47 (69.1%)
Network21 (30.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low66 (97.1%)
High2 (2.9%)
Unknown0 (0.0%)
User Interaction
None11 (16.2%)
Unknown0 (0.0%)
Required57 (83.8%)
Privileges Required
Low15 (22.1%)
High0 (0.0%)
None53 (77.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (68 CVEs).

68 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Visual Studio Code Remote Code Execution Vulnerability
Oct 11, 20227.873NOYES
Visual Studio Code Remote Code Execution Vulnerability
May 10, 20228.851NONO
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Jun 9, 20269.640NONO
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vuln
Mar 5, 20197.840NONO
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Jul 14, 20268.836NONO
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
May 12, 20268.835NONO
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a s
May 12, 20268.835NONO
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally.
Jul 14, 20268.434NONO
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Sep 12, 20259.834NONO
Visual Studio Code Remote Code Execution Vulnerability
Dec 15, 20217.831NONO

Exploit Exposure

Signals from CVEs in this product scope (68 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (68 CVEs).

Media Mentions

Signals from CVEs in this product scope (68 CVEs).

Top CNAs Publishing CVEs For Visual Studio Code

Top CWEs

Versions

No cataloged versions.