CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

visual_studio_code

52 known vulnerabilities · sorted by CVSS score

CVE-2020-1416
HIGH8.8

An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.

microsoft / azure_storage_explorer+6
Network
Published Jul 14, 2020
Page 1 of 3
CVE-2026-21518
HIGH8.8

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

microsoft / visual_studio_code
Network
Published Feb 10, 2026
CVE-2025-55319
HIGH8.8

Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.

microsoft / visual_studio_code
Network
Published Sep 12, 2025
CVE-2024-26165
HIGH8.8

Visual Studio Code Elevation of Privilege Vulnerability

microsoft / visual_studio_code
Network
Published Mar 12, 2024
CVE-2024-43488
HIGH8.8

Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector.

microsoft / visual_studio_code
Network
Published Oct 8, 2024
CVE-2022-30129
HIGH8.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft / visual_studio_code
Network
Published May 10, 2022
CVE-2022-21991
HIGH8.1

Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability

microsoft / visual_studio_code
Network
Published Feb 9, 2022
CVE-2025-64660
HIGH8.0

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.

microsoft / visual_studio_code
Network
Published Nov 20, 2025
CVE-2026-21523
HIGH8.0

Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network.

microsoft / visual_studio_code
Network
Published Feb 10, 2026
CVE-2021-31214
HIGH7.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft / visual_studio_code
Local
Published May 11, 2021
CVE-2021-28471
HIGH7.8

Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability

microsoft / visual_studio_code
Local
Published Apr 13, 2021
CVE-2021-31211
HIGH7.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft / visual_studio_code
Local
Published May 11, 2021
CVE-2020-17148
HIGH7.8

Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability

microsoft / visual_studio_code
Local
Published Dec 10, 2020
CVE-2019-1414
HIGH7.8

An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer, aka 'Visual Studio Code Elevation of Privilege Vulnerability'.

microsoft / visual_studio_code
Local
Published Jan 24, 2020
CVE-2023-21779
HIGH7.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft / visual_studio_code
Local
Published Jan 10, 2023
CVE-2021-27060
HIGH7.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft / visual_studio_code
Local
Published Mar 11, 2021
CVE-2018-0597
HIGH7.8

Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

microsoft / visual_studio_code
Local
Published Jun 26, 2018
CVE-2019-0728
HIGH7.8

A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.

microsoft / visual_studio_code
Local
Published Mar 5, 2019
CVE-2021-34479
HIGH7.8

Microsoft Visual Studio Spoofing Vulnerability

microsoft / visual_studio_code
Local
Published Jul 14, 2021
CVE-2021-42322
HIGH7.8

Visual Studio Code Elevation of Privilege Vulnerability

microsoft / visual_studio_code
Local
Published Nov 10, 2021