VYPR

Vendor CVEs

Elastic

All CVEs

371 total · sorted by risk
  • CVE-2016-10366MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

  • CVE-2016-10365MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.

  • CVE-2015-9056MedJun 16, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.

  • CVE-2017-8440MedJun 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

  • CVE-2017-8439MedJun 5, 2017
    risk 0.40cvss 6.1epss 0.01

    Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.

  • CVE-2023-46674MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    An issue was identified that allowed the unsafe deserialization of java objects from hadoop or spark configuration properties that could have been modified by authenticated users. Elastic would like to thank Yakov Shafranovich, with Amazon Web Services for reporting this issue.

  • CVE-2021-37937MedNov 22, 2023
    risk 0.38cvss 5.9epss 0.01

    An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with a service account, it is possible that the API key could be created with higher privileges than intended. Using this vulnerability, a compromised Fleet-Server…

  • CVE-2023-31421MedOct 26, 2023
    risk 0.38cvss 5.9epss 0.00

    It was discovered that when acting as TLS clients, Beats, Elastic Agent, APM Server, and Fleet Server did not verify whether the server certificate is valid for the target IP address; however, certificate signature validation is still performed. More specifically, when the…

  • CVE-2018-17247MedDec 20, 2018
    risk 0.38cvss 5.9epss 0.01

    Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable…

  • CVE-2018-3825MedSep 19, 2018
    risk 0.38cvss 5.9epss 0.01

    In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 a default master encryption key is used in the process of granting ZooKeeper access to Elasticsearch clusters. Unless explicitly overwritten, this master key is predictable across all ECE deployments. If an attacker can…

  • CVE-2017-8444MedSep 29, 2017
    risk 0.38cvss 5.9epss 0.01

    The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the client-forwarder and ZooKeeper they could potentially obtain sensitive data.

  • CVE-2017-8449MedJun 16, 2017
    risk 0.38cvss 5.9epss 0.01

    X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.

  • CVE-2026-26932MedFeb 26, 2026
    risk 0.37cvss 5.7epss 0.00

    Improper Validation of Array Index (CWE-129) in the PostgreSQL protocol parser in Packetbeat can lead Denial of Service via Input Data Manipulation (CAPEC-153). An attacker can send a specially crafted packet causing a Go runtime panic that terminates the Packetbeat process.…

  • CVE-2025-37731MedDec 15, 2025
    risk 0.37cvss 6.8epss 0.00

    Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.

  • CVE-2023-6687MedDec 12, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Elastic Agent…

  • CVE-2023-49922MedDec 12, 2023
    risk 0.37cvss 6.8epss 0.01

    An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to Elasticsearch failed with any 4xx HTTP status code except 409 or 429. Depending on the nature of the event that Beats or…

  • CVE-2024-37284MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of alternate encoding occurs when Elastic Defend on Windows systems attempts to scan a file or process encoded as a multibyte character. This leads to an uncaught exception causing Elastic Defend to crash which in turn will prevent it from quarantining the file…

  • CVE-2017-8445MedAug 18, 2017
    risk 0.36cvss 5.5epss 0.00

    An error was found in the X-Pack Security TLS trust manager for versions 5.0.0 to 5.5.1. If reloading the trust material fails the trust manager will be replaced with an instance that trusts all certificates. This could allow any node using any certificate to join a cluster. The…

  • CVE-2026-78609MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate…

  • CVE-2026-78599MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a…

  • CVE-2026-78586MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded…

  • CVE-2026-78608MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to an internal Kibana APM integration function, allowing any authenticated Kibana user to read APM server credentials that…

  • CVE-2026-72682MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only low, read-level Agent Builder privileges could submit a specially crafted request that causes Kibana…

  • CVE-2026-72654MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Execution with Unnecessary Privileges (CWE-250) in the Kibana machine learning feature can lead to information disclosure via Privilege Abuse (CAPEC-122). An operation available to users holding only read access to the machine learning feature was performed with an internal…

  • CVE-2026-72652MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana…

  • CVE-2026-72644MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only the low-privileged feature access required to use the Observability AI Assistant can submit a specially crafted request that…

  • CVE-2026-72628MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data…

  • CVE-2026-63138MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the…

  • CVE-2026-33465MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption,…

  • CVE-2026-72674MedAug 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the Kibana Playground for RAG feature was neither bounded in length nor…

  • CVE-2026-72673MedAug 13, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics private locations can be shared with more than one space, and deleting one removes it…

  • CVE-2026-56146MedJul 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on…

  • CVE-2026-49094MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containing an oversized input value to an analytics collections management endpoint.…

  • CVE-2026-42400MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload that is processed prior to authorization checks, causing excessive memory and…

  • CVE-2026-42399MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentially increasing amounts of memory by submitting a specially crafted Timelion…

  • CVE-2026-33459MedApr 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with access to the automatic import feature can submit specially crafted requests with excessively large input values. When multiple…

  • CVE-2026-0528MedJan 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Array Index (CWE-129) exists in Metricbeat can allow an attacker to cause a Denial of Service through Input Data Manipulation (CAPEC-153) via specially crafted, malformed payloads sent to the Graphite server metricset or Zookeeper server metricset.…

  • CVE-2025-68384MedDec 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

  • CVE-2025-68383MedDec 18, 2025
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a…

  • CVE-2025-37732MedDec 15, 2025
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to render HTML tags within a user’s browser via the integration package upload functionality. This issue is related to ESA-2025-17 (CVE-2025-25018)…

  • CVE-2025-37728MedOct 7, 2025
    risk 0.35cvss 5.4epss 0.00

    Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which…

  • CVE-2024-52979MedMay 1, 2025
    risk 0.35cvss 6.5epss 0.01

    Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.

  • CVE-2024-11390MedMay 1, 2025
    risk 0.35cvss 5.4epss 0.00

    Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files. The attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.

  • CVE-2024-52980MedApr 8, 2025
    risk 0.35cvss 6.5epss 0.01

    A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster…

  • CVE-2024-12539MedDec 17, 2024
    risk 0.35cvss 6.5epss 0.00

    An issue was discovered where improper authorization controls affected certain queries that could allow a malicious actor to circumvent Document Level Security in Elasticsearch and get access to documents that their roles would normally not allow.

  • CVE-2024-37283MedAug 12, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By default the log level is set to info, where no leak occurs.

  • CVE-2021-37936MedNov 18, 2022
    risk 0.35cvss 5.4epss 0.00

    It was discovered that Kibana was not sanitizing document fields containing HTML snippets. Using this vulnerability, an attacker with the ability to write documents to an elasticsearch index could inject HTML. When the Discover app highlighted a search term containing the HTML,…

  • CVE-2022-23711MedApr 21, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in Kibana could expose sensitive information related to Elastic Stack monitoring in the Kibana page source. Elastic Stack monitoring features provide a way to keep a pulse on the health and performance of your Elasticsearch cluster. Authentication with a…

  • CVE-2022-23707MedFeb 11, 2022
    risk 0.35cvss 5.4epss 0.01

    An XSS vulnerability was found in Kibana index patterns. Using this vulnerability, an authenticated user with permissions to create index patterns can inject malicious javascript into the index pattern which could execute against other users

  • CVE-2021-22137MedMay 13, 2021
    risk 0.35cvss 5.3epss 0.01

    In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search queries. This could result in the…

Page 5 of 8