Bitnami package
powershell
pkg:bitnami/powershell
Vulnerabilities (30)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-50523 | Hig | 7.8 | >= 7.4.0, < 7.4.19 | 7.4.19 | Aug 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | |
| CVE-2026-70338 | Hig | 7.8 | >= 7.4.0, < 7.4.19 | 7.4.19 | Aug 11, 2026 | Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2026-70337 | Hig | 8.8 | >= 7.4.0, < 7.4.19 | 7.4.19 | Aug 11, 2026 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-59119 | Hig | 7.3 | >= 7.6.0, < 7.6.5 | 7.6.5 | Aug 11, 2026 | Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-58612 | Hig | 7.4 | >= 7.6.0, < 7.6.5 | 7.6.5 | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network. | |
| CVE-2026-26171 | Hig | 7.5 | >= 7.5.0, < 7.5.6 | 7.5.6 | Apr 14, 2026 | Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-26143 | Hig | 7.8 | >= 7.4.0, < 7.4.14 | 7.4.14 | Apr 14, 2026 | Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | |
| CVE-2025-25004 | Hig | 7.3 | >= 7.4.0, < 7.4.13 | 7.4.13 | Oct 14, 2025 | Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-49734 | Hig | 7.0 | >= 7.4.0, < 7.4.12 | 7.4.12 | Sep 9, 2025 | Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally. | |
| CVE-2025-30399 | Hig | 7.5 | >= 7.4.0, < 7.4.11 | 7.4.11 | Jun 13, 2025 | Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network. | |
| CVE-2020-36846 | Cri | 9.8 | >= 7.0.0, < 7.0.9 | 7.0.9 | May 30, 2025 | A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression | |
| CVE-2025-21171 | Hig | 7.5 | >= 7.5.0, < 7.5.2 | 7.5.2 | Jan 14, 2025 | .NET Remote Code Execution Vulnerability | |
| CVE-2024-30045 | Med | 6.3 | >= 7.4.0, < 7.4.3 | 7.4.3 | May 14, 2024 | .NET and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-21409 | Hig | 7.3 | >= 7.2.0, < 7.2.19 | 7.2.19 | Apr 9, 2024 | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability | |
| CVE-2024-26190 | Hig | 7.5 | >= 7.3.0, < 7.3.12 | 7.3.12 | Mar 12, 2024 | Microsoft QUIC Denial of Service Vulnerability | |
| CVE-2024-21392 | Hig | 7.5 | >= 7.3.0, < 7.3.12 | 7.3.12 | Mar 12, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-0057 | Cri | 9.1 | >= 7.2.0, < 7.2.18 | 7.2.18 | Jan 9, 2024 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability | |
| CVE-2023-36013 | Med | 6.5 | >= 7.2.0, < 7.2.17 | 7.2.17 | Nov 20, 2023 | PowerShell Information Disclosure Vulnerability | |
| CVE-2023-21538 | Hig | 7.5 | >= 7.2.0, <= 7.2.0 | — | Jan 10, 2023 | .NET Denial of Service Vulnerability | |
| CVE-2022-41121 | Hig | 7.8 | >= 7.2.0, <= 7.2.0 | — | Dec 13, 2022 | Windows Graphics Component Elevation of Privilege Vulnerability |
- affected >= 7.4.0, < 7.4.19fixed 7.4.19
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
- affected >= 7.4.0, < 7.4.19fixed 7.4.19
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
- affected >= 7.4.0, < 7.4.19fixed 7.4.19
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
- affected >= 7.6.0, < 7.6.5fixed 7.6.5
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
- affected >= 7.6.0, < 7.6.5fixed 7.6.5
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
- affected >= 7.5.0, < 7.5.6fixed 7.5.6
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 7.4.0, < 7.4.14fixed 7.4.14
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
- affected >= 7.4.0, < 7.4.13fixed 7.4.13
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
- affected >= 7.4.0, < 7.4.12fixed 7.4.12
Improper restriction of communication channel to intended endpoints in Windows PowerShell allows an authorized attacker to elevate privileges locally.
- affected >= 7.4.0, < 7.4.11fixed 7.4.11
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
- affected >= 7.0.0, < 7.0.9fixed 7.0.9
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression
- affected >= 7.5.0, < 7.5.2fixed 7.5.2
.NET Remote Code Execution Vulnerability
- affected >= 7.4.0, < 7.4.3fixed 7.4.3
.NET and Visual Studio Remote Code Execution Vulnerability
- affected >= 7.2.0, < 7.2.19fixed 7.2.19
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
- affected >= 7.3.0, < 7.3.12fixed 7.3.12
Microsoft QUIC Denial of Service Vulnerability
- affected >= 7.3.0, < 7.3.12fixed 7.3.12
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 7.2.0, < 7.2.18fixed 7.2.18
NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability
- affected >= 7.2.0, < 7.2.17fixed 7.2.17
PowerShell Information Disclosure Vulnerability
- affected >= 7.2.0, <= 7.2.0
.NET Denial of Service Vulnerability
- affected >= 7.2.0, <= 7.2.0
Windows Graphics Component Elevation of Privilege Vulnerability
Page 1 of 2