Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-72665 Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Acce… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72664 Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functi… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72663 Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, de… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72661 Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72660 Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72659 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specia… No fix yet Fix from $4,0002026-08-13 HIGH 7.3 CVE-2026-72658 Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72657 Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipulating User-Controlled Variab… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72656 Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allo… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72653 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authe… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72651 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authe… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72648 Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosu… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72647 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticate… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72645 Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authent… No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-72643 Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-72642 The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory ad… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72640 The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespa… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72639 Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72638 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holdin… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-72636 Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). … No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-72632 Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API k… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-72631 Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy … No fix yet Fix from $4,0002026-08-13 HIGH 7.1 CVE-2026-72630 Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to m… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-72629 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Prop… No fix yet Fix from $4,9002026-08-13 HIGH 8.6 CVE-2026-49864 wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download … No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-49089 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query … No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-19747 A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fu… No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-18164 An undocumented hard-coded credential, shared by all device units, is authorized to bypass authentication. This allows an attacker within Bluetooth r… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-17004 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an infinite loop. I No fix yet Fix from $4,9002026-08-13 HIGH 7.8 CVE-2026-16987 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable. I No fix yet Fix from $4,9002026-08-13