Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Packetbeat MEDIUM 5.7
CVE-2026-26933

Improper Validation of Array Index (CWE-129) in multiple protocol parser components in Packetbeat can lead Denial of Service via Input Data Manipulat…

Fix: 8.19.11 / 9.2.5+
Fix from $1,600 2026-03-19
Packetbeat HIGH 7.5
CVE-2026-26932

Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (…

Fix: 8.19.11 / 9.2.5+
Fix from $1,950 2026-02-26
Packetbeat MEDIUM 6.5
CVE-2025-68381

Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Packetbeat MEDIUM 6.5
CVE-2025-68382

Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leadi…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Packetbeat MEDIUM 5.3
CVE-2025-68388

Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of…

Fix: 8.19.9 / 9.1.9+
Fix from $1,600 2025-12-18
Kibana MEDIUM 6.7
CVE-2020-7017

In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a re…

Fix: 6.8.11 / 7.8.1+
Fix from $1,600 2020-07-27
Packetbeat HIGH 7.5
CVE-2017-11480

Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for Postgr…

Fix: 5.6.4+
Fix from $1,950 2017-12-08
Cloud Enterprise MEDIUM 5.9
CVE-2017-8444

The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man …

Mitigation only
Fix from $1,600 2017-09-29
Logstash HIGH 7.8
CVE-2017-14730

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory tre…

Patch available
Fix from $1,950 2017-09-25
X Pack MEDIUM 5.3
CVE-2017-8446

The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vuln…

Fix: after 5.5.1
Fix from $1,600 2017-08-18
Elasticsearch HIGH 7.5
CVE-2015-4165

The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, i…

No fix yet
Fix from $1,950 2017-08-09
Output Plugin MEDIUM 6.5
CVE-2016-10362

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

Fix: after 5.0.0
Fix from $1,600 2017-06-16
Elasticsearch MEDIUM 5.0
CVE-2015-5531EPSS 95%

Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to sn…

Fix: after 1.6.0
Fix from $1,600 2015-08-17