Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-63263 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticat… Elasticsearch 8.19.19 / 9.3.8+ Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-63144 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged … Elasticsearch 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-63260 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker w… Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-63261 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authentica… Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 MEDIUM 5.0 CVE-2026-63142 Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound … Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-63141 Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without … Kibana 9.3.8 / 9.4.4+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-63140 Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search requ… Elasticsearch 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 HIGH 7.1 CVE-2026-56147 Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity co… Kibana 8.19.18 / 9.3.7+ Fix from $1,9502026-07-21 MEDIUM 6.5 CVE-2026-63136 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A user with search p… Elasticsearch 8.19.15 / 9.2.9+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-63139 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privil… Kibana 8.19.19 / 9.3.8+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-56144 Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorizatio… Elasticsearch 8.19.18 / 9.3.7+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-56145 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged aut… Elasticsearch 8.19.18 / 9.3.7+ Fix from $1,6002026-07-21 MEDIUM 5.4 CVE-2026-56146 Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential informati… Kibana 9.4.3+ Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-42397 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut… Kibana 9.3.7 / 9.4.4+ Fix from $1,6002026-07-21 HIGH 8.0 CVE-2026-49091 Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can… Kibana 7.17.15 / 8.11.1+ Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-49090 Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated u… Elasticsearch 7.17.24 / 8.15.0+ Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-56150 Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). … Fleet Server 8.19.11 / 9.2.5+ Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-56151 Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submi… Kibana 8.19.17 / 9.3.6+ Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-56152 Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrai… Endpoint Security 8.19.13 / 9.2.7+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-56148 Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can sub… Elasticsearch 8.19.17 / 9.3.6+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-49087 Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An aut… Kibana 8.19.15 / 9.3.4+ Fix from $1,6002026-07-01 HIGH 7.7 CVE-2026-49093 Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configure… Kibana 9.3.3+ Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-49094 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with … Kibana 8.19.16+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-49095 Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with F… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 HIGH 7.7 CVE-2026-42398 Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured con… Kibana 9.2.8 / 9.3.2+ Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-42399 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privil… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-42400 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can s… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 MEDIUM 6.5 CVE-2026-33464 Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user hol… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 MEDIUM 5.4 CVE-2026-42401 Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elas… Kibana 8.19.16 / 9.3.5+ Fix from $1,6002026-05-28 HIGH 7.3 CVE-2026-33462 A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could cr… Kibana 8.19.16 / 9.3.5+ Fix from $1,9502026-05-28