Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Kibana HIGH 7.7
CVE-2026-26938

Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read …

Mitigation only
Fix from $1,950 2026-02-26
Kibana HIGH 8.8
CVE-2024-37288

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th…

Mitigation only
Fix from $1,950 2024-09-09
Kibana HIGH 7.5
CVE-2023-31422

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana v…

Mitigation only
Fix from $1,950 2023-10-26
Kibana HIGH 8.8
CVE-2023-31415

Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request…

Mitigation only
Fix from $1,950 2023-05-04
Elasticsearch HIGH 7.5
CVE-2021-22146EPSS 28%

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting…

No fix yet
Fix from $1,950 2021-07-21
Kibana MEDIUM 6.5
CVE-2019-7618

A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is p…

Mitigation only
Fix from $1,600 2019-10-01
Elasticsearch MEDIUM 5.9
CVE-2018-17247

Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw…

Mitigation only
Fix from $1,600 2018-12-20
X Pack CRITICAL 9.8
CVE-2018-3822

X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. …

Mitigation only
Fix from $2,300 2018-03-30
Kibana MEDIUM 6.1
CVE-2017-11481

Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensiti…

Mitigation only
Fix from $1,600 2017-12-08
Kibana MEDIUM 6.1
CVE-2017-11482

The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vuln…

Mitigation only
Fix from $1,600 2017-12-08
X Pack HIGH 8.8
CVE-2017-8448

An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch…

Mitigation only
Fix from $1,950 2017-09-29
X Pack MEDIUM 6.5
CVE-2017-8447

An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a…

Mitigation only
Fix from $1,600 2017-09-29
Kibana MEDIUM 6.1
CVE-2017-11479

Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2017-09-29
Logstash MEDIUM 5.9
CVE-2015-5619

Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the L…

No fix yet
Fix from $1,600 2017-08-09
Logstash HIGH 7.5
CVE-2015-5378

Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash serve…

No fix yet
Fix from $1,950 2017-06-27
Kibana Reporting HIGH 8.8
CVE-2016-1000218

Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an …

Mitigation only
Fix from $1,950 2017-06-16
X Pack HIGH 7.5
CVE-2017-8450

X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an…

Mitigation only
Fix from $1,950 2017-06-16
Kibana MEDIUM 6.5
CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any …

Mitigation only
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2016-10366

Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

Mitigation only
Fix from $1,600 2017-06-16
Kibana MEDIUM 6.1
CVE-2017-8439

Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain s…

Mitigation only
Fix from $1,600 2017-06-05
Kibana MEDIUM 6.1
CVE-2017-8440

Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitiv…

Mitigation only
Fix from $1,600 2017-06-05
Logstash HIGH 7.5
CVE-2014-4326

Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o…

Mitigation only
Fix from $1,950 2014-07-22