CVE-2026-70338 — CVSS 7.8 (high): Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security…
CVE-2026-26143 — CVSS 7.8 (high): Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50523 — CVSS 7.8 (high): Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker…
CVE-2020-1108 — CVSS 7.5 (high): A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully…
CVE-2025-30399 — CVSS 7.5 (high): Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
CVE-2026-58612 — CVSS 7.4 (high): Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
CVE-2026-59119 — CVSS 7.3 (high): Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-25004 — CVSS 7.3 (high): Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-49734 — CVSS 7.0 (high): Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate…
CVE-2020-0951 — CVSS 6.7 (medium): <p>A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass…
CVE-2020-8927 — CVSS 5.3 (medium): A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot"…