VYPR

Vendor CVEs

Elastic

All CVEs

330 total · sorted by risk
  • CVE-2021-22151LowNov 22, 2023
    risk 0.20cvss 3.1epss 0.01

    It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

  • CVE-2020-7020LowOct 22, 2020
    risk 0.20cvss 3.1epss 0.01

    Elasticsearch versions before 6.8.13 and 7.9.2 contain a document disclosure flaw when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain complex queries. This could result in the search disclosing the…

  • CVE-2021-37939LowNov 18, 2021
    risk 0.18cvss 2.7epss 0.00

    It was discovered that Kibana’s JIRA connector & IBM Resilient connector could be used to return HTTP response data on internal hosts, which may be intentionally hidden from public view. Using this vulnerability, a malicious user with the ability to create connectors, could…

  • CVE-2015-5531Aug 17, 2015
    risk 0.10cvss epss 0.95

    Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.

  • CVE-2021-22133LowFeb 10, 2021
    risk 0.09cvss 2.4epss 0.01

    The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an…

  • CVE-2021-22143LowNov 22, 2023
    risk 0.07cvss 2.1epss 0.01

    The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application error. Normally, the APM agent will sanitize sensitive HTTP header details before sending the information to the APM server. During an application error it is…

  • CVE-2015-3337May 1, 2015
    risk 0.06cvss epss 0.33

    Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2026-63263MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation.…

  • CVE-2026-63262MedJul 22, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

  • CVE-2026-63261MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory…

  • CVE-2026-63260MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request…

  • CVE-2026-63259MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

  • CVE-2026-63145MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a…

  • CVE-2026-63144MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within…

  • CVE-2026-63143MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the…

  • CVE-2026-63142MedJul 21, 2026
    risk 0.00cvss 5.0epss 0.00

    Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that…

  • CVE-2026-49091HigJul 1, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently…

  • CVE-2026-49090MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk request that causes sustained high CPU consumption, which can render the affected node…

  • CVE-2026-56152MedJul 1, 2026
    risk 0.00cvss 5.3epss 0.00

    Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are…

  • CVE-2026-56151MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially crafted Fleet policy input that is not correctly validated, which can render Fleet agent, server, and policy…

  • CVE-2026-56150MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specially crafted request to an upload endpoint that causes excessive memory consumption, which may…

  • CVE-2026-56149MedJul 1, 2026
    risk 0.00cvss 4.9epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted machine learning request that causes excessive memory consumption,…

  • CVE-2026-56148MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query that causes excessive resource consumption while the request is processed, which may render the…

  • CVE-2026-49088MedJul 1, 2026
    risk 0.00cvss 4.4epss 0.00

    Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, sensitive request header values could be recorded in application logs, where they may…

  • CVE-2026-49087MedJul 1, 2026
    risk 0.00cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted bulk deletion request that causes excessive resource consumption, which may render…

  • CVE-2015-8131Dec 7, 2015
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Elasticsearch Kibana before 4.1.3 and 4.2.x before 4.2.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2015-4152Jun 15, 2015
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in the file output plugin in Elasticsearch Logstash before 1.4.3 allows remote attackers to write to arbitrary files via vectors related to dynamic field references in the path option.

  • CVE-2015-4093Jun 15, 2015
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Elasticsearch Kibana 4.x before 4.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-6439Oct 10, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2014-4326Jul 22, 2014
    risk 0.00cvss epss 0.03

    Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

Page 7 of 7