Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2022-38777
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi…
Endgame
3.62.3 / 7.17.9+
MEDIUM 6.5
CVE-2022-38778
A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated user to perform a request that …
Kibana
0.2.1 / 7.17.9+
HIGH 7.8
CVE-2022-38775
An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privi…
Endpoint Security
8.4.1+
HIGH 7.8
CVE-2022-38774
An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which could allow unprivileged users …
Endgame
7.17.7 / 8.4.0+
MEDIUM 5.4
CVE-2021-37936
It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to …
Kibana
7.14.1+
MEDIUM 6.1
CVE-2021-22141
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in…
Kibana
6.8.16 / 7.13.0+
MEDIUM 5.3
CVE-2022-23716
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment…
Elastic Cloud Enterprise
3.1.1+
MEDIUM 6.5
CVE-2022-23715
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystor…
Elastic Cloud Enterprise
3.4.0+
HIGH 7.8
CVE-2022-23714
A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could all…
Endpoint Security
after 8.2.3
MEDIUM 6.1
CVE-2022-23713
A cross-site-scripting (XSS) vulnerability was discovered in the Vega Charts Kibana integration which could allow arbitrary JavaScript to be executed…
Kibana
7.17.5+
HIGH 7.5
CVE-2022-23712EPSS 8%
A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticse…
Elasticsearch
8.2.1+
MEDIUM 5.3
CVE-2022-23711
A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring …
Kibana
7.17.3 / 8.1.3+
MEDIUM 6.1
CVE-2022-23710
A cross-site-scripting (XSS) vulnerability was discovered in the Data Preview Pane (previously known as Index Pattern Preview Pane) which could allow…
Kibana
after 7.17.0
MEDIUM 5.4
CVE-2022-23707
An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns ca…
Kibana
7.17.0+
HIGH 7.8
CVE-2021-37941
A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application runn…
Apm Agent
after 1.26.0
MEDIUM 6.8
CVE-2021-37940
An information disclosure via GET request server-side request forgery vulnerability was discovered with the Workplace Search Github Enterprise Server…
Enterprise Search
7.16.0+
HIGH 8.8
CVE-2021-22149
Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alternate rou…
Enterprise Search
7.14.0+
HIGH 8.8
CVE-2021-22148
Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as their cre…
Enterprise Search
7.14.0+
MEDIUM 6.5
CVE-2021-22147
Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated user gaining…
Elasticsearch
7.14.0+
MEDIUM 6.5
CVE-2021-22144
In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial of service attack was identifi…
Elasticsearch
6.8.17 / 7.13.3+
HIGH 7.5
CVE-2021-22146EPSS 28%
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting…
Elasticsearch
No fix yet
MEDIUM 6.5
CVE-2021-22145EPSS 76%
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queri…
Elasticsearch
after 7.13.3
HIGH 7.5
CVE-2021-22140
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta fe…
Elastic App Search
7.12.0+
MEDIUM 6.5
CVE-2021-22139
Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack of timeout or a limit on the r…
Kibana
7.12.1+
MEDIUM 5.3
CVE-2021-22137
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries…
Elasticsearch
6.8.15 / 7.11.2+
MEDIUM 5.3
CVE-2021-22135
Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch suggester and profile API when Docu…
Elasticsearch
6.8.15 / 7.11.2+
MEDIUM 6.1
CVE-2020-27816
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the ori…
Kibana
after 4.7
HIGH 8.8
CVE-2020-7018
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface. If a user is given the �developer� role, t…
Enterprise Search
7.9.0+
MEDIUM 6.5
CVE-2020-7019
In Elasticsearch before 7.9.0 and 6.8.12 a field disclosure flaw was found when running a scrolling search with Field Level Security. If a user runs …
Elasticsearch
6.8.12 / 7.9.0+
HIGH 8.8
CVE-2020-7014
The fix for CVE-2020-7009 was found to be incomplete. Elasticsearch versions from 6.7.0 to 6.8.7 and 7.0.0 to 7.6.1 contain a privilege escalation fl…
Elasticsearch
after 7.6.1