Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2020-7015
Kibana versions before 6.8.9 and 7.7.0 contains a stored XSS flaw in the TSVB visualization. An attacker who is able to edit or create a TSVB visuali…
Kibana
6.8.10 / 7.7.1+
HIGH 8.8
CVE-2020-7012EPSS 18%
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privile…
Kibana
after 7.6.2
HIGH 7.5
CVE-2020-7010
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determin…
Elastic Cloud On Kubernetes
1.1.0+
HIGH 7.2
CVE-2020-7013
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualiza…
Kibana
6.8.9 / 7.7.0+
MEDIUM 6.1
CVE-2020-7011
Elastic App Search versions before 7.7.0 contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Referenc…
Elastic App Search
7.7.0+
HIGH 8.8
CVE-2020-7009
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create API keys. …
Elasticsearch
6.8.8 / 7.6.2+
MEDIUM 5.4
CVE-2019-7621
Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visualizations. An attacker with th…
Kibana
6.8.6 / 7.5.1+
HIGH 7.5
CVE-2019-7620
Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthenticated user who is able to …
Logstash
6.8.4 / 7.4.1+
MEDIUM 5.3
CVE-2019-7619
Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. An unauthenticated attacker c…
Elasticsearch
after 7.3.2
MEDIUM 6.5
CVE-2019-7618
A local file disclosure flaw was found in Elastic Code versions 7.3.0, 7.3.1, and 7.3.2. If a malicious code repository is imported into Code it is p…
Kibana
Mitigation only
HIGH 7.2
CVE-2019-7617
When the Elastic APM agent for Python versions before 5.1.0 is run as a CGI script, there is a variable name clash flaw if a remote attacker can cont…
Apm Agent
5.1.0+
HIGH 7.4
CVE-2019-7615
A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trusted server CA certificate via …
Apm Agent Ruby
2.9.0+
MEDIUM 5.9
CVE-2019-7614
A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a request. On a system with multiple…
Elasticsearch
6.8.2 / 7.2.1+
CRITICAL 10.0
CVE-2019-7609 KEVEPSS 95%
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion …
Kibana
5.6.15 / 6.6.1+
CRITICAL 9.8
CVE-2019-7612
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified …
Logstash
5.6.15 / 6.6.1+
CRITICAL 9.0
CVE-2019-7610
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.securi…
Kibana
5.6.15 / 6.6.1+
HIGH 8.1
CVE-2019-7611
A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Level Security are disabled and…
Elasticsearch
5.6.15 / 6.6.1+
HIGH 7.5
CVE-2019-7613
Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain characters into a log entry could pr…
Winlogbeat
5.6.16 / 6.6.2+
MEDIUM 6.1
CVE-2019-7608
Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to obtain sensitive information f…
Kibana
5.6.15 / 6.6.1+
CRITICAL 9.8
CVE-2018-17245
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF report…
Kibana
after 6.4.2
CRITICAL 9.8
CVE-2018-17246EPSS 82%
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console…
Kibana
5.6.13 / 6.4.3+
MEDIUM 6.5
CVE-2018-17244
Elasticsearch Security versions 6.4.0 to 6.4.2 contain an error in the way request headers are applied to requests when using the Active Directory, L…
Elasticsearch
after 6.4.2
MEDIUM 5.9
CVE-2018-17247
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw…
Elasticsearch
Mitigation only
HIGH 8.8
CVE-2018-3831
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API…
Elasticsearch
5.6.12 / 6.4.1+
MEDIUM 6.1
CVE-2018-3830
Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain s…
Kibana
after 6.4.1
MEDIUM 5.3
CVE-2018-3829
In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invalid roles…
Elastic Cloud Enterprise
1.1.4+
HIGH 8.1
CVE-2018-3827
A sensitive data disclosure flaw was found in the Elasticsearch repository-azure (formerly elasticsearch-cloud-azure) plugin. When the repository-azu…
Azure Repository
after 6.2.4
HIGH 7.5
CVE-2018-3828
Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 contain an information exposure vulnerability. It was discovered that certain exception condit…
Elastic Cloud Enterprise
1.1.4+
MEDIUM 6.5
CVE-2018-3826
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are …
Elasticsearch
after 6.2.4
MEDIUM 6.1
CVE-2018-3824
X-Pack Machine Learning versions before 6.2.4 and 5.6.9 had a cross-site scripting (XSS) vulnerability. If an attacker is able to inject data into an…
Elasticsearch X Pack
5.6.9 / 6.2.4+