visual_studio_2022_version_17.14 vulnerabilities
CVEs whose affected-version data names the visual_studio_2022_version_17.14 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
30 CVEsRSS
CVE-2026-69806High· 7.0Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-69805High· 7.5External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69522High· 8.8Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-69439High· 8.8Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
Heap-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69304Medium· 5.9Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVE-2026-58649Medium· 6.5Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62900Medium· 5.9.NET Information Disclosure Vulnerability
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62902Medium· 6.5.NET Information Disclosure Vulnerability
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62901High· 7.5.NET Denial of Service Vulnerability
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-62909High· 7.8.NET Elevation of Privilege Vulnerability
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-70354High· 7.8.NET Core Remote Code Execution Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62897High· 7.0.NET Framework Remote Code Execution Vulnerability
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62871High· 7.8.NET Elevation of Privilege Vulnerability
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62898High· 7.5Microsoft QUIC Information Disclosure Vulnerability
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899Medium· 5.9.NET Security Feature Bypass Vulnerability
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50646High· 7.8.NET Framework Remote Code Execution Vulnerability
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-47305High· 7.8Visual Studio Remote Code Execution Vulnerability
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-50650High· 7.8.NET Framework Elevation of Privilege Vulnerability
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-50527High· 7.5.NET Framework Denial of Service Vulnerability
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-47303High· 8.8ASP.NET Core Elevation of Privilege Vulnerability
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-47300High· 8.8ASP.NET Core Elevation of Privilege Vulnerability
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVE-2026-50526High· 7.0.NET Tampering Vulnerability
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
CVE-2026-47304High· 8.1.NET Security Feature Bypass Vulnerability
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50524High· 7.5.NET Framework Denial of Service Vulnerability
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50648High· 7.5.NET Framework Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
CVE-2026-50528High· 8.2.NET Security Feature Bypass Vulnerability
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-50525High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-50659Medium· 6.5.NET Spoofing Vulnerability
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
CVE-2026-50651High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVE-2026-47302High· 7.5.NET Denial of Service Vulnerability
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.