cbcvebase.

Microsoft Powershell vulnerabilities

23 known vulnerabilities affecting microsoft/powershell.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH16MEDIUM5

Vulnerabilities

Page 1 of 2
CVE-2018-8327P2CRITICALCVSS 9.8fixed in 1.7.02018-07-11
CVE-2018-8327 [CRITICAL] CVE-2018-8327: A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor S A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension.
nvd
CVE-2020-0605P3HIGHCVSS 8.8≥ 0, < 7.0.02024-02-02
CVE-2020-0605 [HIGH] PowerShell is subject to remote code execution vulnerability PowerShell is subject to remote code execution vulnerability # Microsoft Security Advisory CVE-2020-0605: .NET Framework Remote Code Execution Vulnerability ## Executive Summary A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current
ghsaosv
CVE-2024-0057P3CRITICALCVSS 9.8≥ 7.2, < 7.2.18≥ 7.3, < 7.3.11+1 more2024-01-09
CVE-2024-0057 [CRITICAL] CWE-20 CVE-2024-0057: NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
nvd
CVE-2026-70337P3HIGHCVSS 8.8≥ 7.4, < 7.4.19.0≥ 7.5, < 7.5.10.0+1 more2026-08-11
CVE-2026-70337 [HIGH] CWE-23 CVE-2026-70337: Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-26171P3HIGHCVSS 7.5≥ 7.5, < 7.5.6≥ 7.6, < 7.6.12026-04-14
CVE-2026-26171 [HIGH] CWE-400 CVE-2026-26171: Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a net Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
nvd
CVE-2026-50523P3HIGHCVSS 7.8≥ 7.4, < 7.4.19.0≥ 7.5, < 7.5.10.0+1 more2026-08-14
CVE-2026-50523 [HIGH] CWE-77 CVE-2026-50523: Improper neutralization of special elements used in a command ('command injection') in Microsoft Pow Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
nvd
CVE-2026-58612P3HIGHCVSS 7.5≥ 7.4, < 7.4.19.0≥ 7.5, < 7.5.10.0+1 more2026-08-11
CVE-2026-58612 [HIGH] CWE-918 CVE-2026-58612: Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to d Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2020-1108P3HIGHCVSS 7.5v7.02020-05-21
CVE-2020-1108 [HIGH] CVE-2020-1108: A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web req A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could ex
nvd
CVE-2026-70338P3HIGHCVSS 7.8≥ 7.4, < 7.4.19.0≥ 7.5, < 7.5.10.0+1 more2026-08-11
CVE-2026-70338 [HIGH] CWE-94 CVE-2026-70338: Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthor Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2026-26143P3HIGHCVSS 7.8≥ 7.4, < 7.4.14≥ 7.5, < 7.5.52026-04-14
CVE-2026-26143 [HIGH] CWE-20 CVE-2026-26143: Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a securi Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
nvd
CVE-2025-30399P3HIGHCVSS 7.5≥ 7.4, < 7.4.11≥ 7.5, < 7.5.22025-06-13
CVE-2025-30399 [HIGH] CWE-426 CVE-2025-30399: Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
nvd
CVE-2020-0951P3MEDIUMCVSS 6.7≥ 7.0, < 7.0.8≥ 7.1, < 7.1.5+1 more2020-09-11
CVE-2020-0951 [MEDIUM] CVE-2020-0951: <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) whi A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement. An attacker who successfully exploited this vulnerability could execute PowerShell commands that would be blocked by WDAC. To exploit the vulnerability, an attacker need administrator access on a local machine
nvd
CVE-2026-59119P3HIGHCVSS 7.3≥ 7.4, < 7.4.19.0≥ 7.5, < 7.5.10.0+1 more2026-08-11
CVE-2026-59119 [HIGH] CWE-276 CVE-2026-59119: Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privi Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-21409P3HIGHCVSS 7.3≥ 7.2, < 7.2.19≥ 7.3, < 7.3.12+1 more2024-04-09
CVE-2024-21409 [HIGH] CWE-416 CVE-2024-21409: .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2020-8927P3MEDIUMCVSS 6.5≥ 7.0, < 7.0.9≥ 7.1, < 7.1.6+1 more2020-09-15
CVE-2020-8927 [MEDIUM] CWE-130 CVE-2020-8927: A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or later. If one cannot update, we recomm
nvd
CVE-2025-25004P3HIGHCVSS 7.3≥ 7.4, < 7.4.13≥ 7.5, < 7.5.42025-10-14
CVE-2025-25004 [HIGH] CWE-284 CVE-2025-25004: Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
nvd
CVE-2022-41121P3HIGHCVSS 7.8v7.2v7.32022-12-13
CVE-2022-41121 [HIGH] CVE-2022-41121: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2022-23267P3HIGHCVSS 7.5≥ 7.0, < 7.0.11≥ 7.2, < 7.2.42022-05-10
CVE-2022-23267 [HIGH] CVE-2022-23267: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-21392P3HIGHCVSS 7.5≥ 7.3, < 7.3.12v7.42024-03-12
CVE-2024-21392 [HIGH] CWE-400 CVE-2024-21392: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2024-30045P3MEDIUMCVSS 6.3≥ 7.4, < 7.4.32024-05-14
CVE-2024-30045 [MEDIUM] CWE-122 CVE-2024-30045: .NET and Visual Studio Remote Code Execution Vulnerability .NET and Visual Studio Remote Code Execution Vulnerability
nvd