VYPR
Vendor

Elastic

Products
63
CVEs
330
Across products
389
Status
Private

Products

63
View all 63 products →

Recent CVEs

330
View all 330 CVEs →
  • CVE-2015-1427CriKEVFeb 17, 2015
    risk 0.87cvss 9.8epss 1.00

    The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

  • CVE-2019-7609CriKEVMar 25, 2019
    risk 0.81cvss 10.0epss 0.95

    Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing…

  • CVE-2018-17246CriDec 20, 2018
    risk 0.70cvss 9.8epss 0.82

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing…

  • CVE-2014-3120HigKEVJul 28, 2014
    risk 0.68cvss 8.1epss 0.89

    The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user…

  • CVE-2025-25015CriMar 5, 2025
    risk 0.64cvss 9.9epss 0.01

    Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only…

  • CVE-2024-37288CriSep 9, 2024
    risk 0.64cvss 9.9epss 0.01

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-fo…

  • CVE-2018-17245CriDec 20, 2018
    risk 0.64cvss 9.8epss 0.02

    Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating PDF reports. If a report requests external resources plaintext credentials are included in the HTTP request that could be recovered by an…

  • CVE-2018-3822CriMar 30, 2018
    risk 0.64cvss 9.8epss 0.02

    X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with…

  • CVE-2020-7012HigJun 3, 2020
    risk 0.62cvss 8.8epss 0.18

    Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to…

  • CVE-2025-25014CriMay 6, 2025
    risk 0.60cvss 9.1epss 0.21

    A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.

  • CVE-2025-37729CriOct 13, 2025
    risk 0.59cvss 9.1epss 0.01

    Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted string where Jinjava variables are evaluated.

  • CVE-2024-52975CriJan 23, 2025
    risk 0.59cvss 9.0epss 0.00

    An issue was identified in Fleet Server where Fleet policies that could contain sensitive information were logged on INFO and ERROR log levels. The nature of the sensitive information largely depends on the integrations enabled.

  • CVE-2024-37285CriNov 14, 2024
    risk 0.59cvss 9.1epss 0.01

    A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful attack requires a malicious user to have a combination of both specific Elasticsearch indices privileges…

  • CVE-2024-37287CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.

  • CVE-2023-31422CriOct 26, 2023
    risk 0.59cvss 9.0epss 0.01

    An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has…

  • CVE-2015-5377CriMar 6, 2018
    risk 0.58cvss 9.8epss 0.15

    Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appears to claim that CVE-2015-3253 and CVE-2015-5377 are the same vulnerability

  • CVE-2026-72642HigAug 13, 2026
    risk 0.57cvss 8.8epss

    The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying…

  • CVE-2025-37736HigNov 7, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can call APIs that should not be allowed. The list of APIs that are affected by this issue is: post:/platform/configuration/security/service-accounts…

  • CVE-2025-25018HigOct 10, 2025
    risk 0.57cvss 8.7epss 0.00

    Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

  • CVE-2025-25009HigOct 7, 2025
    risk 0.57cvss 8.7epss 0.00

    Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.