Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-25009 Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. Kibana 8.18.8 / 8.19.5+ Fix from $1,6002025-10-07 MEDIUM 6.5 CVE-2025-25010 Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access a… Kibana 9.0.6 / 9.1.3+ Fix from $1,6002025-08-28 MEDIUM 5.4 CVE-2025-25012 URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via … Kibana 7.17.29 / 8.17.8+ Fix from $1,6002025-06-25 HIGH 8.8 CVE-2024-43706 Improper authorization in Kibana can lead to privilege abuse via a direct HTTP request to a Synthetic monitor endpoint. Kibana after 8.12.0 Fix from $1,9502025-06-10 CRITICAL 9.8 CVE-2025-25014EPSS 21% A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints. Kibana 8.17.6+ Fix from $2,3002025-05-06 HIGH 7.8 CVE-2024-52976 Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code v… Elastic Agent 7.17.25 / 8.15.4+ Fix from $1,9502025-05-01 HIGH 7.5 CVE-2024-52979 Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial … Elasticsearch 7.17.25 / 8.16.0+ Fix from $1,9502025-05-01 MEDIUM 5.4 CVE-2024-11390 Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML a… Kibana 7.17.24 / 8.12.0+ Fix from $1,6002025-05-01 HIGH 7.1 CVE-2023-46669 Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and… Elastic Agent 8.15.0+ Fix from $1,9502025-05-01 CRITICAL 9.8 CVE-2024-12556 Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal. Kibana 8.16.4 / 8.17.2+ Fix from $2,3002025-04-08 HIGH 7.5 CVE-2024-52981 An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects co… Elasticsearch 7.17.24 / 8.15.1+ Fix from $1,9502025-04-08 MEDIUM 6.5 CVE-2024-52974 An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful att… Kibana 7.17.23 / 8.15.1+ Fix from $1,6002025-04-08 MEDIUM 6.5 CVE-2024-52980 A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause… Elasticsearch 8.15.1+ Fix from $1,6002025-04-08 CRITICAL 9.9 CVE-2025-25015 Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions … Kibana 8.16.6 / 8.17.3+ Fix from $2,3002025-03-05 MEDIUM 6.5 CVE-2024-43708 An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted payload to a number of inputs in … Kibana 7.17.23 / 8.15.0+ Fix from $1,6002025-01-23 MEDIUM 6.5 CVE-2024-52972 An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/metrics/snapshot.… Kibana 7.17.23 / 8.15.0+ Fix from $1,6002025-01-23 MEDIUM 6.5 CVE-2024-43707 An issue was identified in Kibana where a user without access to Fleet can view Elastic Agent policies that could contain sensitive information. The … Kibana 8.15.0+ Fix from $1,6002025-01-23 MEDIUM 6.5 CVE-2024-52973 An allocation of resources without limits or throttling in Kibana can lead to a crash caused by a specially crafted request to /api/log_entries/summa… Kibana 7.17.23 / 8.14.2+ Fix from $1,6002025-01-21 HIGH 7.5 CVE-2024-43709 An allocation of resources without limits or throttling in Elasticsearch can lead to an OutOfMemoryError exception resulting in a crash via a special… Elasticsearch 7.17.21 / 8.13.3+ Fix from $1,9502025-01-21 MEDIUM 6.5 CVE-2024-12539 An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Leve… Elasticsearch 8.16.2+ Fix from $1,6002024-12-17 HIGH 7.2 CVE-2024-37285 A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A … Kibana after 8.15.0 Fix from $1,9502024-11-14 HIGH 8.8 CVE-2024-37288 A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. Th… Kibana Mitigation only Fix from $1,9502024-09-09 HIGH 7.2 CVE-2024-37287 A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write ac… Kibana 7.17.23 / 8.14.2+ Fix from $1,9502024-08-13 MEDIUM 6.5 CVE-2024-37283 An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debu… Elastic Agent 8.15.0+ Fix from $1,6002024-08-12 MEDIUM 6.5 CVE-2024-37286 APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific… Apm Server 8.14.0+ Fix from $1,6002024-08-03 HIGH 7.5 CVE-2024-23444 It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate S… Elasticsearch 7.17.23 / 8.13.0+ Fix from $1,9502024-07-31 MEDIUM 6.5 CVE-2024-37281 An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously craft… Kibana 7.17.23 / 8.14.0+ Fix from $1,6002024-07-30 MEDIUM 6.5 CVE-2023-49921 An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents o… Elasticsearch 7.17.16 / 8.11.2+ Fix from $1,6002024-07-26 CRITICAL 9.8 CVE-2024-37282 It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently … Elastic Cloud Enterprise 3.7.2+ Fix from $2,3002024-06-28 MEDIUM 6.1 CVE-2024-23442 An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted … Kibana 7.17.22 / 8.14.0+ Fix from $1,6002024-06-14