Known vulnerabilities in Visual Studio Code 1.33.1

Vendor: Microsoft
Version: 1.33.1
Software CPE: cpe:2.3:a:microsoft:vscode:*:*:*:*:*:*:*:*
Total vulnerabilities: 54
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Visual Studio Code version 1.33.1 Visual Studio Code 1.33.1 is affected by 54 vulnerabilities: 1 critical, 25 high, 18 medium, 10 low Critical High Medium Low

Vulnerabilities (54)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU148277 - Use of Incorrectly-Resolved Name or Reference
CVE-2026-81383
CWE-706 Medium
No
No
1.136.2 09.09.2026 SB2026090915
#VU148276 - Insufficiently Protected Credentials
CVE-2026-81381
CWE-522 Medium
No
No
1.136.2 09.09.2026 SB2026090915
#VU148275 - Command injection
CVE-2026-81380
CWE-77 Medium
No
No
1.136.2 09.09.2026 SB2026090915
#VU148274 - Not Failing Securely (\'Failing Open\')
CVE-2026-81379
CWE-636 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU148273 - Interpretation Conflict
CVE-2026-81378
CWE-436 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU148272 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-81377
CWE-22 Medium
No
No
1.136.2 09.09.2026 SB2026090915
#VU148271 - Incomplete Comparison with Missing Factors
CVE-2026-81376
CWE-1023 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU148270 - Server-Side Request Forgery (SSRF)
CVE-2026-81357
CWE-918 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU148269 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-81356
CWE-444 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU148216 - Authorization Bypass Through User-Controlled Key
CVE-2026-78462
CWE-639 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU148215 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-78461
CWE-22 Medium
No
No
1.136.2 09.09.2026 SB2026090915
#VU148031 - Incomplete List of Disallowed Inputs
CVE-2026-70334
CWE-184 High
No
No
1.136.2 09.09.2026 SB2026090915
#VU141863 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-70336
CWE-94 High
No
No
1.132.1 12.08.2026 SB20260812229
#VU141862 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-70335
CWE-78 High
No
No
1.132.1 12.08.2026 SB20260812229
#VU141837 - Not Failing Securely (\'Failing Open\')
CVE-2026-69306
CWE-636 High
No
No
1.132.1 12.08.2026 SB20260812229
#VU141836 - Incorrect Authorization
CVE-2026-69278
CWE-863 High
No
No
1.132.1 12.08.2026 SB20260812229
#VU141835 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-69320
CWE-78 High
No
No
1.132.1 12.08.2026 SB20260812229
#VU141738 - Command injection
CVE-2026-47285
CWE-77 Medium
No
No
1.132.1 12.08.2026 SB20260812229
#VU141737 - Missing Authorization
CVE-2026-59113
CWE-862 High
No
No
1.132.1 12.08.2026 SB20260812229
#VU141733 - Authorization Bypass Through User-Controlled Key
CVE-2026-58650
CWE-639 High
No
No
1.132.1 12.08.2026 SB20260812229


Showing elements 1 - 20 out of 54