Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endgame HIGH 7.8
CVE-2022-38777

An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi…

Fix: 3.62.3 / 7.17.9+
Fix from $1,950 2023-02-08
Kibana MEDIUM 6.5
CVE-2022-38778

A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that …

Fix: 0.2.1 / 7.17.9+
Fix from $1,600 2023-02-08
Endpoint Security HIGH 7.8
CVE-2022-38775

An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi…

Fix: 8.4.1+
Fix from $1,950 2023-01-26
Endgame HIGH 7.8
CVE-2022-38774

An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users …

Fix: 7.17.7 / 8.4.0+
Fix from $1,950 2023-01-26
Kibana MEDIUM 5.4
CVE-2021-37936

It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to …

Fix: 7.14.1+
Fix from $1,600 2022-11-18
Kibana MEDIUM 6.1
CVE-2021-22141

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in…

Fix: 6.8.16 / 7.13.0+
Fix from $1,600 2022-11-18
Elastic Cloud Enterprise MEDIUM 5.3
CVE-2022-23716

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment…

Fix: 3.1.1+
Fix from $1,600 2022-09-28
Elastic Cloud Enterprise MEDIUM 6.5
CVE-2022-23715

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystor…

Fix: 3.4.0+
Fix from $1,600 2022-08-25
Endpoint Security HIGH 7.8
CVE-2022-23714

A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could all…

Fix: after 8.2.3
Fix from $1,950 2022-07-06
Kibana MEDIUM 6.1
CVE-2022-23713

A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed…

Fix: 7.17.5+
Fix from $1,600 2022-07-06
Elasticsearch HIGH 7.5
CVE-2022-23712EPSS 8%

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticse…

Fix: 8.2.1+
Fix from $1,950 2022-06-06
Kibana MEDIUM 5.3
CVE-2022-23711

A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring …

Fix: 7.17.3 / 8.1.3+
Fix from $1,600 2022-04-21
Kibana MEDIUM 6.1
CVE-2022-23710

A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow…

Fix: after 7.17.0
Fix from $1,600 2022-03-03
Kibana MEDIUM 5.4
CVE-2022-23707

An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns ca…

Fix: 7.17.0+
Fix from $1,600 2022-02-11
Apm Agent HIGH 7.8
CVE-2021-37941

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application runn…

Fix: after 1.26.0
Fix from $1,950 2021-12-08
Enterprise Search MEDIUM 6.8
CVE-2021-37940

An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server…

Fix: 7.16.0+
Fix from $1,600 2021-12-07
Enterprise Search HIGH 8.8
CVE-2021-22149

Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou…

Fix: 7.14.0+
Fix from $1,950 2021-09-15
Enterprise Search HIGH 8.8
CVE-2021-22148

Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their cre…

Fix: 7.14.0+
Fix from $1,950 2021-09-15
Elasticsearch MEDIUM 6.5
CVE-2021-22147

Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining…

Fix: 7.14.0+
Fix from $1,600 2021-09-15
Elasticsearch MEDIUM 6.5
CVE-2021-22144

In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identifi…

Fix: 6.8.17 / 7.13.3+
Fix from $1,600 2021-07-26
Elasticsearch HIGH 7.5
CVE-2021-22146EPSS 28%

All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting…

No fix yet
Fix from $1,950 2021-07-21
Elasticsearch MEDIUM 6.5
CVE-2021-22145EPSS 76%

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queri…

Fix: after 7.13.3
Fix from $1,600 2021-07-21
Elastic App Search HIGH 7.5
CVE-2021-22140

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta fe…

Fix: 7.12.0+
Fix from $1,950 2021-05-13
Kibana MEDIUM 6.5
CVE-2021-22139

Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the r…

Fix: 7.12.1+
Fix from $1,600 2021-05-13
Elasticsearch MEDIUM 5.3
CVE-2021-22137

In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries…

Fix: 6.8.15 / 7.11.2+
Fix from $1,600 2021-05-13
Elasticsearch MEDIUM 5.3
CVE-2021-22135

Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Docu…

Fix: 6.8.15 / 7.11.2+
Fix from $1,600 2021-05-13
Kibana MEDIUM 6.1
CVE-2020-27816

The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the ori…

Fix: after 4.7
Fix from $1,600 2020-12-02
Enterprise Search HIGH 8.8
CVE-2020-7018

Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t…

Fix: 7.9.0+
Fix from $1,950 2020-08-18
Elasticsearch MEDIUM 6.5
CVE-2020-7019

In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs …

Fix: 6.8.12 / 7.9.0+
Fix from $1,600 2020-08-18
Elasticsearch HIGH 8.8
CVE-2020-7014

The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl…

Fix: after 7.6.1
Fix from $1,950 2020-06-03