Known vulnerabilities in PowerShell
Vendor:
Microsoft
Software:
PowerShell
Software CPE:
cpe:2.3:a:microsoft:powershell:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
7.6.4
7.5.9
7.4.18
7.6.3
7.5.8
7.4.17
7.6.2
7.5.7
7.4.16
7.6.1
7.5.6
7.4.15
7.6.0
7.5.5
7.4.14
7.5.4
7.4.13
7.5.3
7.4.12
7.5.2
7.4.11
7.4.10
7.5.1
7.4.9
7.4.8
7.5.0
7.4.7
7.4.6
7.2.24
7.4.5
7.2.23
7.4.4
7.2.22
7.4.3
7.2.21
7.2.20
7.4.2
7.3.12
7.2.19
7.4.1
7.3.11
7.2.18
7.4.0
7.3.10
7.2.17
7.3.9
7.2.16
7.3.8
7.2.15
7.3.7
7.2.14
7.3.6
7.2.13
7.3.5
7.2.12
7.3.4
7.3.3
7.3.2
7.3.1
7.2.11
7.2.10
7.2.9
7.2.8
7.2.7
7.2.6
7.2.5
7.2.4
7.2.3
7.2.2
7.2.1
7.1.7
7.1.6
7.1.5
7.1.4
7.1.3
7.1.2
7.1.1
7.1.0
7.0.13
7.0.12
7.0.11
7.0.10
7.0.9
7.0.8
7.0.7
7.0.6
7.0.5
7.0.4
7.0.3
7.0.2
7.0.1
7.0.0
6.2.7
6.2.6
6.2.5
6.2.4
6.2.3
6.2.2
6.2.1
6.2.0
6.1.6
6.1.5
6.1.4
6.1.3
6.1.2
6.1.1
6.1.0
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
0.6.0
0.5.0
0.4.0
0.3.0
0.2.0
0.1.0
7.3.0
7.2.0
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU126136 - Improper input validation CVE-2026-26143 |
CWE-20 | High | 7.4.14 | 15.04.2026 |
SB2026041548 |
||
| #VU117111 - Improper Access Control CVE-2025-25004 |
CWE-284 | Low | 7.4.13 7.4.13 | 14.10.2025 |
SB2025101497 |
||
| #VU102801 - Heap-based Buffer Overflow CVE-2025-21171 |
CWE-122 | Medium | 7.5.0 | 15.01.2025 |
SB2025011545 SB2025011647 SB2025011672 and 2 more |
||
| #VU83310 - Exposure of sensitive information to an unauthorized actor CVE-2023-36013 |
CWE-200 | Medium | 7.2.17, 7.3.10, 7.4.0 | 20.11.2023 |
SB2023112063 |
||
| #VU74917 - Uncontrolled Search Path Element CVE-2023-28260 |
CWE-427 | Medium | 7.2.11, 7.3.4 | 11.04.2023 |
SB2023041173 SB2023041206 SB2023111618 |
||
| #VU70180 - Improper input validation CVE-2022-41076 |
CWE-20 | Medium | - | 13.12.2022 |
SB2022121357 |
||
| #VU58975 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing) CVE-2021-43896 |
CWE-451 | Low | - | 14.12.2021 |
SB2021121491 |