powershell_7.4 vulnerabilities
CVEs whose affected-version data names the powershell_7.4 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-50523High· 7.8Microsoft PowerShell Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
CVE-2026-70338High· 7.8Microsoft PowerShell Security Feature Bypass Vulnerability
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-70337High· 8.8Microsoft PowerShell Remote Code Execution Vulnerability
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
CVE-2026-58612High· 7.4PowerShell Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
CVE-2026-59119High· 7.3PowerShell Elevation of Privilege Vulnerability
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.