Elastic kayıtları
elastic üreticisine ait 349 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %0,9
- Silahlaştırılmış
- 5 · %1,4
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %30,1
- Yayından KEV’e ortanca
- 2593 gün
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption30
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-863 Incorrect Authorization26
- CWE-770 Allocation of Resources Without Limits or Throttling26
- CWE-532 Insertion of Sensitive Information into Log File23
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor17
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
349 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2015-1427Silahlaştırılmış | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection meelastic · elasticsearch | Kritik9,8 | KEV | %99,9 | 17 Şub 2015 |
99Hemen | CVE-2019-7609Silahlaştırılmış | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Kritik10,0 | KEV | %95,3 | 25 Mar 2019 |
89Hemen | CVE-2014-3120Silahlaştırılmış | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expelastic · elasticsearch · CWE-284 | Yüksek8,1 | KEV | %88,6 | 28 Tem 2014 |
64Bu hafta | CVE-2018-17246Kavram kanıtı | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.elastic · kibana · CWE-73 | Kritik9,8 | — | %82,3 | 20 Ara 2018 |
49Planlayın | CVE-2021-22145Silahlaştırılmış | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.elastic · elasticsearch · CWE-200 | Orta6,5 | — | %76,2 | 21 Tem 2021 |
49Planlayın | CVE-2023-31419Kavram kanıtı | Elasticsearch StackOverflow vulnerabilityelastic · elasticsearch · CWE-121 | Yüksek7,5 | — | %61,7 | 26 Eki 2023 |
45Planlayın | CVE-2025-25014Kavram kanıtı | Kibana arbitrary code execution via prototype pollutionelastic · kibana · CWE-1321 | Kritik9,8 | — | %21,5 | 6 May 2025 |
43Planlayın | CVE-2015-5377Kavram kanıtı | Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.elastic · elasticsearch · CWE-74 | Kritik9,8 | — | %14,3 | 6 Mar 2018 |
41Planlayın | CVE-2021-22146Kavram kanıtı | All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.elastic · elasticsearch | Yüksek7,5 | — | %35,8 | 21 Tem 2021 |
40Planlayın | CVE-2020-7012Silahlaştırılmış | Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.elastic · kibana · CWE-94 | Yüksek8,8 | — | %18,2 | 3 Haz 2020 |
40Planlayın | CVE-2019-7612İstismar yok | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.elastic · logstash · CWE-209 | Kritik9,8 | — | %2,4 | 25 Mar 2019 |
39İzleyin | CVE-2018-3822İstismar yok | X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM trelastic · x-pack · CWE-287 | Kritik9,8 | — | %1,6 | 30 Mar 2018 |
39İzleyin | CVE-2018-17245İstismar yok | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating Pelastic · kibana · CWE-201 | Kritik9,8 | — | %1,5 | 20 Ara 2018 |
39İzleyin | CVE-2025-25015İstismar yok | Kibana arbitrary code execution via prototype pollutionelastic · kibana · CWE-1321 | Kritik9,9 | — | %1,3 | 5 Mar 2025 |
39İzleyin | CVE-2026-33466İstismar yok | Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Writeelastic · logstash · CWE-22 | Kritik9,8 | — | %0,8 | 8 Nis 2026 |
39İzleyin | CVE-2024-37282İstismar yok | It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subselastic · elastic cloud enterprise · CWE-285 | Kritik9,8 | — | %0,6 | 28 Haz 2024 |
39İzleyin | CVE-2024-12556İstismar yok | Kibana Prototype Pollution can lead to code injectionelastic · kibana · CWE-1321 | Kritik9,8 | — | %0,5 | 8 Nis 2025 |
37İzleyin | CVE-2019-7610İstismar yok | Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.elastic · kibana · CWE-94 | Kritik9,0 | — | %3,9 | 25 Mar 2019 |
36İzleyin | CVE-2018-3831İstismar yok | Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vielastic · elasticsearch · CWE-200 | Yüksek8,8 | — | %2,0 | 19 Eyl 2018 |
36İzleyin | CVE-2026-72676İstismar yok | Improper Control of Generation of Code in Fleet Server Leading to Code Injectionelastic · kibana · CWE-94 | Kritik9,1 | — | %0,5 | 13 Ağu 2026 |
36İzleyin | CVE-2023-46668İstismar yok | Elastic Endpoint Insertion of Sensitive Information into Log Fileelastic · endpoint · CWE-532 | Kritik9,1 | — | %0,3 | 25 Eki 2023 |
35İzleyin | CVE-2020-7009İstismar yok | Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create Aelastic · elasticsearch · CWE-266 | Yüksek8,8 | — | %1,6 | 31 Mar 2020 |
35İzleyin | CVE-2020-7014İstismar yok | The fix for CVE-2020-7009 was found to be incomplete.elastic · elasticsearch · CWE-266 | Yüksek8,8 | — | %1,5 | 3 Haz 2020 |
35İzleyin | CVE-2020-7018İstismar yok | Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.elastic · enterprise search · CWE-266 | Yüksek8,8 | — | %1,1 | 18 Ağu 2020 |
35İzleyin | CVE-2017-8438İstismar yok | Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.elastic · x-pack · CWE-284 | Yüksek8,8 | — | %1,0 | 5 Haz 2017 |
- CVE-2015-142799Hemen
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100elastic · elasticsearch17 Şub 2015
- CVE-2019-760999Hemen
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %95elastic · kibana25 Mar 2019
- CVE-2014-312089Hemen
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %89elastic · elasticsearch28 Tem 2014
- CVE-2018-1724664Bu hafta
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
KritikCVSS 9,8Kavram kanıtıEPSS %82elastic · kibana20 Ara 2018
- CVE-2021-2214549Planlayın
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
OrtaCVSS 6,5SilahlaştırılmışEPSS %76elastic · elasticsearch21 Tem 2021
- CVE-2023-3141949Planlayın
Elasticsearch StackOverflow vulnerability
YüksekCVSS 7,5Kavram kanıtıEPSS %62elastic · elasticsearch26 Eki 2023
- CVE-2025-2501445Planlayın
Kibana arbitrary code execution via prototype pollution
KritikCVSS 9,8Kavram kanıtıEPSS %21elastic · kibana6 May 2025
- CVE-2015-537743Planlayın
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.
KritikCVSS 9,8Kavram kanıtıEPSS %14elastic · elasticsearch6 Mar 2018
- CVE-2021-2214641Planlayın
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
YüksekCVSS 7,5Kavram kanıtıEPSS %36elastic · elasticsearch21 Tem 2021
- CVE-2020-701240Planlayın
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.
YüksekCVSS 8,8SilahlaştırılmışEPSS %18elastic · kibana3 Haz 2020
- CVE-2019-761240Planlayın
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
KritikCVSS 9,8İstismar yokEPSS %2elastic · logstash25 Mar 2019
- CVE-2018-382239İzleyin
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM tr
KritikCVSS 9,8İstismar yokEPSS %2elastic · x-pack30 Mar 2018
- CVE-2018-1724539İzleyin
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P
KritikCVSS 9,8İstismar yokEPSS %2elastic · kibana20 Ara 2018
- CVE-2025-2501539İzleyin
Kibana arbitrary code execution via prototype pollution
KritikCVSS 9,9İstismar yokEPSS %1elastic · kibana5 Mar 2025
- CVE-2026-3346639İzleyin
Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write
KritikCVSS 9,8İstismar yokEPSS %1elastic · logstash8 Nis 2026
- CVE-2024-3728239İzleyin
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subs
KritikCVSS 9,8İstismar yokEPSS %1elastic · elastic cloud enterprise28 Haz 2024
- CVE-2024-1255639İzleyin
Kibana Prototype Pollution can lead to code injection
KritikCVSS 9,8İstismar yokEPSS %1elastic · kibana8 Nis 2025
- CVE-2019-761037İzleyin
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.
KritikCVSS 9,0İstismar yokEPSS %4elastic · kibana25 Mar 2019
- CVE-2018-383136İzleyin
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vi
YüksekCVSS 8,8İstismar yokEPSS %2elastic · elasticsearch19 Eyl 2018
- CVE-2026-7267636İzleyin
Improper Control of Generation of Code in Fleet Server Leading to Code Injection
KritikCVSS 9,1İstismar yokEPSS %1elastic · kibana13 Ağu 2026
- CVE-2023-4666836İzleyin
Elastic Endpoint Insertion of Sensitive Information into Log File
KritikCVSS 9,1İstismar yokEPSS %0elastic · endpoint25 Eki 2023
- CVE-2020-700935İzleyin
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create A
YüksekCVSS 8,8İstismar yokEPSS %2elastic · elasticsearch31 Mar 2020
- CVE-2020-701435İzleyin
The fix for CVE-2020-7009 was found to be incomplete.
YüksekCVSS 8,8İstismar yokEPSS %2elastic · elasticsearch3 Haz 2020
- CVE-2020-701835İzleyin
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.
YüksekCVSS 8,8İstismar yokEPSS %1elastic · enterprise search18 Ağu 2020
- CVE-2017-843835İzleyin
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.
YüksekCVSS 8,8İstismar yokEPSS %1elastic · x-pack5 Haz 2017