Vulnerability index

Browse CVEs

221 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2022-38777 An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi… Endgame 3.62.3 / 7.17.9+ Fix from $1,9502023-02-08 MEDIUM 6.5 CVE-2022-38778 A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that … Kibana 0.2.1 / 7.17.9+ Fix from $1,6002023-02-08 HIGH 7.8 CVE-2022-38775 An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi… Endpoint Security 8.4.1+ Fix from $1,9502023-01-26 HIGH 7.8 CVE-2022-38774 An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users … Endgame 7.17.7 / 8.4.0+ Fix from $1,9502023-01-26 MEDIUM 5.4 CVE-2021-37936 It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to … Kibana 7.14.1+ Fix from $1,6002022-11-18 MEDIUM 6.1 CVE-2021-22141 An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in… Kibana 6.8.16 / 7.13.0+ Fix from $1,6002022-11-18 MEDIUM 5.3 CVE-2022-23716 A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment… Elastic Cloud Enterprise 3.1.1+ Fix from $1,6002022-09-28 MEDIUM 6.5 CVE-2022-23715 A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystor… Elastic Cloud Enterprise 3.4.0+ Fix from $1,6002022-08-25 HIGH 7.8 CVE-2022-23714 A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could all… Endpoint Security after 8.2.3 Fix from $1,9502022-07-06 MEDIUM 6.1 CVE-2022-23713 A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed… Kibana 7.17.5+ Fix from $1,6002022-07-06 HIGH 7.5 CVE-2022-23712EPSS 8% A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticse… Elasticsearch 8.2.1+ Fix from $1,9502022-06-06 MEDIUM 5.3 CVE-2022-23711 A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring … Kibana 7.17.3 / 8.1.3+ Fix from $1,6002022-04-21 MEDIUM 6.1 CVE-2022-23710 A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow… Kibana after 7.17.0 Fix from $1,6002022-03-03 MEDIUM 5.4 CVE-2022-23707 An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns ca… Kibana 7.17.0+ Fix from $1,6002022-02-11 HIGH 7.8 CVE-2021-37941 A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application runn… Apm Agent after 1.26.0 Fix from $1,9502021-12-08 MEDIUM 6.8 CVE-2021-37940 An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server… Enterprise Search 7.16.0+ Fix from $1,6002021-12-07 HIGH 8.8 CVE-2021-22149 Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou… Enterprise Search 7.14.0+ Fix from $1,9502021-09-15 HIGH 8.8 CVE-2021-22148 Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their cre… Enterprise Search 7.14.0+ Fix from $1,9502021-09-15 MEDIUM 6.5 CVE-2021-22147 Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining… Elasticsearch 7.14.0+ Fix from $1,6002021-09-15 MEDIUM 6.5 CVE-2021-22144 In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identifi… Elasticsearch 6.8.17 / 7.13.3+ Fix from $1,6002021-07-26 HIGH 7.5 CVE-2021-22146EPSS 28% All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting… Elasticsearch No fix yet Fix from $1,9502021-07-21 MEDIUM 6.5 CVE-2021-22145EPSS 76% A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queri… Elasticsearch after 7.13.3 Fix from $1,6002021-07-21 HIGH 7.5 CVE-2021-22140 Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta fe… Elastic App Search 7.12.0+ Fix from $1,9502021-05-13 MEDIUM 6.5 CVE-2021-22139 Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the r… Kibana 7.12.1+ Fix from $1,6002021-05-13 MEDIUM 5.3 CVE-2021-22137 In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries… Elasticsearch 6.8.15 / 7.11.2+ Fix from $1,6002021-05-13 MEDIUM 5.3 CVE-2021-22135 Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Docu… Elasticsearch 6.8.15 / 7.11.2+ Fix from $1,6002021-05-13 MEDIUM 6.1 CVE-2020-27816 The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the ori… Kibana after 4.7 Fix from $1,6002020-12-02 HIGH 8.8 CVE-2020-7018 Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t… Enterprise Search 7.9.0+ Fix from $1,9502020-08-18 MEDIUM 6.5 CVE-2020-7019 In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs … Elasticsearch 6.8.12 / 7.9.0+ Fix from $1,6002020-08-18 HIGH 8.8 CVE-2020-7014 The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl… Elasticsearch after 7.6.1 Fix from $1,9502020-06-03