cbcvebase.

Microsoft Visual Studio 2022 vulnerabilities

108 known vulnerabilities affecting microsoft/visual_studio_2022.

Total CVEs
108
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH81MEDIUM21

Vulnerabilities

Page 1 of 6
CVE-2023-44487P1HIGHCVSS 7.5KEVPoC≥ 17.0, < 17.2.20≥ 17.4, < 17.4.12+2 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-38180P2HIGHCVSS 7.5KEV≥ 17.2.0, < 17.2.18≥ 17.4.0, < 17.4.10+1 more2023-08-08
CVE-2023-38180 [HIGH] CWE-400 CVE-2023-38180: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2025-55315P1CRITICALCVSS 9.9PoC≥ 17.10.0, < 17.10.20≥ 17.12.10, < 17.12.13+1 more2025-10-14
CVE-2025-55315 [CRITICAL] CWE-444 CVE-2025-55315: Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core all Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
nvd
CVE-2026-47303P2HIGHCVSS 8.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-47303 [HIGH] CWE-90 CVE-2026-47303: Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to ele Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-43498P2CRITICALCVSS 9.8≥ 17.6, < 17.6.21≥ 17.8, < 17.8.16+2 more2024-11-12
CVE-2024-43498 [CRITICAL] CWE-843 CVE-2024-43498: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2026-21256P2HIGHCVSS 8.8≥ 17.14.0, < 17.14.262026-02-10
CVE-2026-21256 [HIGH] CWE-77 CVE-2026-21256: Improper neutralization of special elements used in a command ('command injection') in GitHub Copilo Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-47300P2HIGHCVSS 8.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-47300 [HIGH] CWE-303 CVE-2026-47300: Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker t Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-36049P3CRITICALCVSS 9.8≥ 17.2, < 17.2.22≥ 17.4, < 17.4.14+2 more2023-11-14
CVE-2023-36049 [CRITICAL] CWE-20 CVE-2023-36049: .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2026-47304P3CRITICALCVSS 9.8≥ 17.12.0, < 17.12.22≥ 17.14.0, < 17.14.362026-07-14
CVE-2026-47304 [CRITICAL] CWE-345 CVE-2026-47304: Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2024-0057P3CRITICALCVSS 9.8≥ 17.2, < 17.2.23≥ 17.4, < 17.4.15+2 more2024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2025-49739P3HIGHCVSS 8.8≥ 17.8.0, < 17.8.23≥ 17.10.0, < 17.10.17+2 more2025-07-08
CVE-2025-49739 [HIGH] CWE-59 CVE-2025-49739: Improper link resolution before file access ('link following') in Visual Studio allows an unauthoriz Improper link resolution before file access ('link following') in Visual Studio allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-32178P3HIGHCVSS 7.5≥ 17.12.0, < 17.12.19≥ 17.14.0, < 17.14.302026-04-14
CVE-2026-32178 [HIGH] CWE-138 CVE-2026-32178: Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoof Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-28934P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28934 [HIGH] CWE-121 CVE-2024-28934: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28933P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28933 [HIGH] CWE-191 CVE-2024-28933: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28932P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28932 [HIGH] CWE-122 CVE-2024-28932: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28931P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28931 [HIGH] CWE-190 CVE-2024-28931: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28936P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28936 [HIGH] CWE-190 CVE-2024-28936: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28929P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28929 [HIGH] CWE-190 CVE-2024-28929: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28935P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28935 [HIGH] CWE-122 CVE-2024-28935: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-28930P3HIGHCVSS 8.8≥ 17.4.0, < 17.4.18≥ 17.6.0, < 17.6.14+2 more2024-04-09
CVE-2024-28930 [HIGH] CWE-191 CVE-2024-28930: Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
nvd
Microsoft Visual Studio 2022 vulnerabilities | cvebase