本ページは microsoft visual_studio_2022 に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2026-32203 | Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | [email protected] | 7.5 | 0.26% | 2026-04-14 | 2026-05-06 |
| CVE-2026-32178 | Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | [email protected] | 7.5 | 0.06% | 2026-04-14 | 2026-05-07 |
| CVE-2026-21257 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.0 | 0.04% | 2026-02-10 | 2026-02-11 |
| CVE-2026-21256 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 0.04% | 2026-02-10 | 2026-02-11 |
| CVE-2025-62214 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | [email protected] | 6.7 | 0.04% | 2025-11-11 | 2025-11-17 |
| CVE-2025-55315 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | [email protected] | 9.9 | 1.68% | 2025-10-14 | 2025-10-28 |
| CVE-2025-55248 | Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | [email protected] | 4.8 | 0.02% | 2025-10-14 | 2025-10-23 |
| CVE-2025-55240 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | [email protected] | 7.3 | 0.06% | 2025-10-14 | 2025-10-17 |
| CVE-2025-53773 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally. | [email protected] | 7.8 | 6.60% | 2025-08-12 | 2025-08-15 |
| CVE-2025-49739 | Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.74% | 2025-07-08 | 2025-07-16 |
| CVE-2025-47959 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code over a network. | [email protected] | 7.1 | 0.61% | 2025-06-13 | 2025-07-10 |
| CVE-2025-30399 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | [email protected] | 7.5 | 0.28% | 2025-06-13 | 2025-07-10 |
| CVE-2025-26646 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | [email protected] | 8.0 | 0.10% | 2025-05-13 | 2025-07-10 |
| CVE-2025-32703 | Insufficient granularity of access control in Visual Studio allows an authorized attacker to disclose information locally. | [email protected] | 5.5 | 0.78% | 2025-05-13 | 2025-05-19 |
| CVE-2025-32702 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. | [email protected] | 7.8 | 0.84% | 2025-05-13 | 2025-05-19 |
| CVE-2025-29804 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | [email protected] | 7.3 | 0.48% | 2025-04-08 | 2025-07-10 |
| CVE-2025-29802 | Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | [email protected] | 7.3 | 0.30% | 2025-04-08 | 2025-07-10 |
| CVE-2025-26682 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | [email protected] | 7.5 | 9.56% | 2025-04-08 | 2025-07-09 |
| CVE-2025-25003 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | [email protected] | 7.3 | 0.32% | 2025-03-11 | 2025-07-01 |
| CVE-2025-24998 | Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally. | [email protected] | 7.3 | 0.32% | 2025-03-11 | 2025-07-01 |