Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kibana MEDIUM 5.4
CVE-2025-25009

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.

Fix: 8.18.8 / 8.19.5+
Fix from $1,600 2025-10-07
Kibana MEDIUM 6.5
CVE-2025-25010

Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access a…

Fix: 9.0.6 / 9.1.3+
Fix from $1,600 2025-08-28
Kibana MEDIUM 5.4
CVE-2025-25012

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via …

Fix: 7.17.29 / 8.17.8+
Fix from $1,600 2025-06-25
Kibana HIGH 8.8
CVE-2024-43706

Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint.

Fix: after 8.12.0
Fix from $1,950 2025-06-10
Kibana CRITICAL 9.8
CVE-2025-25014EPSS 21%

A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

Fix: 8.17.6+
Fix from $2,300 2025-05-06
Elastic Agent HIGH 7.8
CVE-2024-52976

Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code v…

Fix: 7.17.25 / 8.15.4+
Fix from $1,950 2025-05-01
Elasticsearch HIGH 7.5
CVE-2024-52979

Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial …

Fix: 7.17.25 / 8.16.0+
Fix from $1,950 2025-05-01
Kibana MEDIUM 5.4
CVE-2024-11390

Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML a…

Fix: 7.17.24 / 8.12.0+
Fix from $1,600 2025-05-01
Elastic Agent HIGH 7.1
CVE-2023-46669

Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and…

Fix: 8.15.0+
Fix from $1,950 2025-05-01
Kibana CRITICAL 9.8
CVE-2024-12556

Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.

Fix: 8.16.4 / 8.17.2+
Fix from $2,300 2025-04-08
Elasticsearch HIGH 7.5
CVE-2024-52981

An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects co…

Fix: 7.17.24 / 8.15.1+
Fix from $1,950 2025-04-08
Kibana MEDIUM 6.5
CVE-2024-52974

An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful att…

Fix: 7.17.23 / 8.15.1+
Fix from $1,600 2025-04-08
Elasticsearch MEDIUM 6.5
CVE-2024-52980

A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause…

Fix: 8.15.1+
Fix from $1,600 2025-04-08
Kibana CRITICAL 9.9
CVE-2025-25015

Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions …

Fix: 8.16.6 / 8.17.3+
Fix from $2,300 2025-03-05
Kibana MEDIUM 6.5
CVE-2024-43708

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in …

Fix: 7.17.23 / 8.15.0+
Fix from $1,600 2025-01-23
Kibana MEDIUM 6.5
CVE-2024-52972

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot.…

Fix: 7.17.23 / 8.15.0+
Fix from $1,600 2025-01-23
Kibana MEDIUM 6.5
CVE-2024-43707

An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The …

Fix: 8.15.0+
Fix from $1,600 2025-01-23
Kibana MEDIUM 6.5
CVE-2024-52973

An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summa…

Fix: 7.17.23 / 8.14.2+
Fix from $1,600 2025-01-21
Elasticsearch HIGH 7.5
CVE-2024-43709

An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a special…

Fix: 7.17.21 / 8.13.3+
Fix from $1,950 2025-01-21
Elasticsearch MEDIUM 6.5
CVE-2024-12539

An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Leve…

Fix: 8.16.2+
Fix from $1,600 2024-12-17
Kibana HIGH 7.2
CVE-2024-37285

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A …

Fix: after 8.15.0
Fix from $1,950 2024-11-14
Kibana HIGH 8.8
CVE-2024-37288

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th…

Mitigation only
Fix from $1,950 2024-09-09
Kibana HIGH 7.2
CVE-2024-37287

A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write ac…

Fix: 7.17.23 / 8.14.2+
Fix from $1,950 2024-08-13
Elastic Agent MEDIUM 6.5
CVE-2024-37283

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debu…

Fix: 8.15.0+
Fix from $1,600 2024-08-12
Apm Server MEDIUM 6.5
CVE-2024-37286

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific…

Fix: 8.14.0+
Fix from $1,600 2024-08-03
Elasticsearch HIGH 7.5
CVE-2024-23444

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate S…

Fix: 7.17.23 / 8.13.0+
Fix from $1,950 2024-07-31
Kibana MEDIUM 6.5
CVE-2024-37281

An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously craft…

Fix: 7.17.23 / 8.14.0+
Fix from $1,600 2024-07-30
Elasticsearch MEDIUM 6.5
CVE-2023-49921

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents o…

Fix: 7.17.16 / 8.11.2+
Fix from $1,600 2024-07-26
Elastic Cloud Enterprise CRITICAL 9.8
CVE-2024-37282

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently …

Fix: 3.7.2+
Fix from $2,300 2024-06-28
Kibana MEDIUM 6.1
CVE-2024-23442

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted …

Fix: 7.17.22 / 8.14.0+
Fix from $1,600 2024-06-14