Vulnerability index

Browse CVEs

22 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.7 CVE-2026-26938 Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read … Kibana Mitigation only Fix from $1,9502026-02-26 HIGH 8.8 CVE-2024-37288 A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th… Kibana Mitigation only Fix from $1,9502024-09-09 HIGH 7.5 CVE-2023-31422 An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana v… Kibana Mitigation only Fix from $1,9502023-10-26 HIGH 8.8 CVE-2023-31415 Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request… Kibana Mitigation only Fix from $1,9502023-05-04 HIGH 7.5 CVE-2021-22146EPSS 28% All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting… Elasticsearch No fix yet Fix from $1,9502021-07-21 MEDIUM 6.5 CVE-2019-7618 A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is p… Kibana Mitigation only Fix from $1,6002019-10-01 MEDIUM 5.9 CVE-2018-17247 Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw… Elasticsearch Mitigation only Fix from $1,6002018-12-20 CRITICAL 9.8 CVE-2018-3822 X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. … X Pack Mitigation only Fix from $2,3002018-03-30 MEDIUM 6.1 CVE-2017-11481 Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensiti… Kibana Mitigation only Fix from $1,6002017-12-08 MEDIUM 6.1 CVE-2017-11482 The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vuln… Kibana Mitigation only Fix from $1,6002017-12-08 HIGH 8.8 CVE-2017-8448 An error was found in the permission model used by X-Pack Alerting 5.0.0 to 5.6.0 whereby users mapped to certain built-in roles could create a watch… X Pack Mitigation only Fix from $1,9502017-09-29 MEDIUM 6.5 CVE-2017-8447 An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index' permissions on an index in a… X Pack Mitigation only Fix from $1,6002017-09-29 MEDIUM 6.1 CVE-2017-11479 Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive informatio… Kibana Mitigation only Fix from $1,6002017-09-29 MEDIUM 5.9 CVE-2015-5619 Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the L… Logstash No fix yet Fix from $1,6002017-08-09 HIGH 7.5 CVE-2015-5378 Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash serve… Logstash No fix yet Fix from $1,9502017-06-27 HIGH 8.8 CVE-2016-1000218 Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an … Kibana Reporting Mitigation only Fix from $1,9502017-06-16 HIGH 7.5 CVE-2017-8450 X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an… X Pack Mitigation only Fix from $1,9502017-06-16 MEDIUM 6.5 CVE-2016-10364 With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any … Kibana Mitigation only Fix from $1,6002017-06-16 MEDIUM 6.1 CVE-2016-10366 Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack. Kibana Mitigation only Fix from $1,6002017-06-16 MEDIUM 6.1 CVE-2017-8439 Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain s… Kibana Mitigation only Fix from $1,6002017-06-05 MEDIUM 6.1 CVE-2017-8440 Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitiv… Kibana Mitigation only Fix from $1,6002017-06-05 HIGH 7.5 CVE-2014-4326 Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb o… Logstash Mitigation only Fix from $1,9502014-07-22