Powershell Exploits

26 exploits tracked across all sources.

Sort: Activity Stars
CVE-2026-8206 GITHUB CRITICAL powershell
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.
by Dungsocool
CVSS 9.8
CVE-2024-23897 GITHUB CRITICAL powershell
Jenkins cli Ampersand Replacement Arbitrary File Read
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read arbitrary files on the Jenkins controller file system.
by Dungsocool
CVSS 9.8
CVE-2024-0670 GITHUB HIGH powershell
Checkmk <2.2.0p23-2.0.0 - Privilege Escalation
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
by dfdxarjy
CVSS 8.8
CVE-2026-45585 GITHUB MEDIUM powershell
Microsoft Windows 11 Version 24H2 - Windows BitLocker Security Feature Bypass Vulnerability
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &quot;YellowKey&quot;. The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available. Mitigation FAQs Should I leverage the temporary mitigation? Microsoft recommends that you consider implementing these mitigations if you are concerned your devices and data are at risk of being compromised or stolen. For example, if your organization’s employees take their work devices home or on business travel. What impact to service availability/management could be caused by implementing the mitigations? Implementing these mitigations will not impact service availability or management operations. Do customers need to revert the changes made to mitigate the vulnerability once the security update to protect against this vulnerability is available? No. The security update will maintain the mitigation's behavior once the security update is installed. I am using TPM+PIN, am I at risk of this vulnerability being exploited No, if you are using TPM+PIN the vulnerability is not exploitable.
by 0xBlackash
CVSS 6.8
CVE-2026-31431 GITHUB HIGH powershell
crypto: algif_aead - Revert to operating out-of-place
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
by makitos666
CVSS 7.8
CVE-2026-6298 GITHUB MEDIUM powershell
Google Chrome < 147.0.7727.101 - Heap-based Buffer Overflow in Skia
Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)
by wnaspy
CVSS 4.3
CVE-2025-53779 GITHUB HIGH powershell
Windows Kerberos - Privilege Escalation
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
by wnaspy
CVSS 7.2
CVE-2025-59287 GITHUB CRITICAL powershell
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthenticated RCE via Deserialization
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
by ross-ns
CVSS 9.8
CVE-2025-11953 GITHUB CRITICAL powershell
react-native-community/cli < 20.0.0 - Unauthenticated OS Command Injection via Metro Development Server
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
by SaidBenaissa
4 stars
CVSS 9.8
CVE-2025-59287 GITHUB CRITICAL powershell
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthenticated RCE via Deserialization
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
by tecxx
12 stars
CVSS 9.8
CVE-2025-59214 GITHUB MEDIUM powershell
Windows File Explorer - Unauthorized Sensitive Information Exposure via Spoofing
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
by rubenformation
52 stars
CVSS 6.5
CVE-2025-24054 GITHUB MEDIUM powershell
Windows 10 1507-22H2 and Windows 11 22H2 - Unauthenticated Spoofing via NTLM File Path Control
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
by rubenformation
52 stars
CVSS 6.5
CVE-2023-34634 EXPLOITDB HIGH powershell
Greenshot < 1.2.10.6 - Remote Code Execution via Insecure .NET Deserialization
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .greenshot file is opened.
by p4r4bellum
CVSS 7.8
CVE-2022-2841 EXPLOITDB LOW powershell
CrowdStrike Falcon <6.31.14505.0/6.42.15610/6.44.15806 - Auth Bypass
A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.40.15409, 6.42.15611 and 6.44.15807 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-206880.
by Fortunato Lodari
CVSS 2.7
EIP-2026-101434 EXPLOITDB powershell
Schneider Electric SpaceLogic C-Bus Home Controller (5200WHC2) - Remote Code Execution
by LiquidWorm
CVE-2021-43326 EXPLOITDB HIGH powershell
Automox Agent <32 - Privilege Escalation
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
by Greg Foss
CVSS 7.8
CVE-2020-11107 EXPLOITDB HIGH powershell
XAMPP <7.2.29, <7.3.16, <7.4.4 - Command Injection
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
by Salman Asad
CVSS 8.8
EIP-2026-118069 EXPLOITDB powershell
Visual Studio Code 1.47.1 - Denial of Service (PoC)
by H.H.A.Ravindu Priyankara
CVE-2018-16156 EXPLOITDB HIGH powershell VERIFIED
PaperStream IP (TWAIN) 1.42.0.5685 - Unauthenticated Local Privilege Escalation via Untrusted Search Path
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported function named ChangeUninstallString. The default install does not contain this library and therefore if any DLL with that name exists in any directory listed in the PATH variable, it can be used to escalate to SYSTEM level privilege.
by 1F98D
CVSS 7.8
CVE-2020-5752 EXPLOITDB HIGH powershell
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
by 1F98D
CVSS 7.8
EIP-2026-117961 EXPLOITDB powershell
Steam Windows Client - Local Privilege Escalation
by AbsoZed
CVE-2018-8474 EXPLOITDB HIGH powershell VERIFIED
Lync for Mac 2011 - Security Feature Bypass via Crafted Message
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.
by nyxgeek
CVSS 7.5
CVE-2018-0880 EXPLOITDB HIGH powershell VERIFIED
Windows Desktop Bridge - Privilege Escalation
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0882.
by Google Security Research
CVSS 7.0
CVE-2017-8550 EXPLOITDB MEDIUM powershell
Skype for Business >= Microsoft Office 2016 Click-to-Run (C2R) - Remote Code Execution
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".
by nyxgeek
CVSS 5.4
CVE-2016-0099 EXPLOITDB HIGH powershell VERIFIED
MS16-032 Secondary Logon Handle Privilege Escalation
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."
by b33f
CVSS 7.8