VulnSea

visual_studio_2026_version_18.8 vulnerabilities

CVEs whose affected-version data names the visual_studio_2026_version_18.8 package (nuget). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-62900Medium· 5.9
1mo ago

.NET Information Disclosure Vulnerability

Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.55%via CVEORG
CVE-2026-62902Medium· 6.5
1mo ago

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 8.0EPSS 0.78%via CVEORG
CVE-2026-62901High· 7.5
1mo ago

.NET Denial of Service Vulnerability

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-62909High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-70354High· 7.8
1mo ago

.NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.29%via CVEORG
CVE-2026-62897High· 7.0
1mo ago

.NET Framework Remote Code Execution Vulnerability

Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 10.0EPSS 0.34%via CVEORG
CVE-2026-62871High· 7.8
1mo ago

.NET Elevation of Privilege Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

TwilightMicrosoft · .NET 8.0EPSS 0.40%via CVEORG
CVE-2026-62898High· 7.5
1mo ago

Microsoft QUIC Information Disclosure Vulnerability

Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · .NET 10.0EPSS 1.1%via CVEORG
CVE-2026-62899Medium· 5.9
1mo ago

.NET Security Feature Bypass Vulnerability

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.

SunlitMicrosoft · .NET 10.0EPSS 0.71%via CVEORG
visual_studio_2026_version_18.8 vulnerabilities (CVEs) · VulnSea