Elastic records
349 published records for vendor elastic.
Researcher profile
- Entered KEV
- 3 · 0.9%
- Weaponized
- 5 · 1.4%
- Pre-auth RCE
- 11
- With a fix record
- 30.1%
- Median publish → KEV
- 2593 days
Recurring classes
- CWE-400 Uncontrolled Resource Consumption30
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28
- CWE-863 Incorrect Authorization26
- CWE-770 Allocation of Resources Without Limits or Throttling26
- CWE-532 Insertion of Sensitive Information into Log File23
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor17
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
349 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2015-1427Weaponized | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection meelastic · elasticsearch | Critical9.8 | KEV | 99.9% | Feb 17, 2015 |
99Now | CVE-2019-7609Weaponized | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Critical10.0 | KEV | 95.3% | Mar 25, 2019 |
89Now | CVE-2014-3120Weaponized | The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expelastic · elasticsearch · CWE-284 | High8.1 | KEV | 88.6% | Jul 28, 2014 |
64This week | CVE-2018-17246Proof of concept | Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.elastic · kibana · CWE-73 | Critical9.8 | — | 82.3% | Dec 20, 2018 |
49Plan | CVE-2021-22145Weaponized | A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.elastic · elasticsearch · CWE-200 | Medium6.5 | — | 76.2% | Jul 21, 2021 |
49Plan | CVE-2023-31419Proof of concept | Elasticsearch StackOverflow vulnerabilityelastic · elasticsearch · CWE-121 | High7.5 | — | 61.7% | Oct 26, 2023 |
45Plan | CVE-2025-25014Proof of concept | Kibana arbitrary code execution via prototype pollutionelastic · kibana · CWE-1321 | Critical9.8 | — | 21.5% | May 6, 2025 |
43Plan | CVE-2015-5377Proof of concept | Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.elastic · elasticsearch · CWE-74 | Critical9.8 | — | 14.3% | Mar 6, 2018 |
41Plan | CVE-2021-22146Proof of concept | All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.elastic · elasticsearch | High7.5 | — | 35.8% | Jul 21, 2021 |
40Plan | CVE-2020-7012Weaponized | Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.elastic · kibana · CWE-94 | High8.8 | — | 18.2% | Jun 3, 2020 |
40Plan | CVE-2019-7612No exploit | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.elastic · logstash · CWE-209 | Critical9.8 | — | 2.4% | Mar 25, 2019 |
39Monitor | CVE-2018-3822No exploit | X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM trelastic · x-pack · CWE-287 | Critical9.8 | — | 1.6% | Mar 30, 2018 |
39Monitor | CVE-2018-17245No exploit | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating Pelastic · kibana · CWE-201 | Critical9.8 | — | 1.5% | Dec 20, 2018 |
39Monitor | CVE-2025-25015No exploit | Kibana arbitrary code execution via prototype pollutionelastic · kibana · CWE-1321 | Critical9.9 | — | 1.3% | Mar 5, 2025 |
39Monitor | CVE-2026-33466No exploit | Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Writeelastic · logstash · CWE-22 | Critical9.8 | — | 0.8% | Apr 8, 2026 |
39Monitor | CVE-2024-37282No exploit | It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subselastic · elastic cloud enterprise · CWE-285 | Critical9.8 | — | 0.6% | Jun 28, 2024 |
39Monitor | CVE-2024-12556No exploit | Kibana Prototype Pollution can lead to code injectionelastic · kibana · CWE-1321 | Critical9.8 | — | 0.5% | Apr 8, 2025 |
37Monitor | CVE-2019-7610No exploit | Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.elastic · kibana · CWE-94 | Critical9.0 | — | 3.9% | Mar 25, 2019 |
36Monitor | CVE-2018-3831No exploit | Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vielastic · elasticsearch · CWE-200 | High8.8 | — | 2.0% | Sep 19, 2018 |
36Monitor | CVE-2026-72676No exploit | Improper Control of Generation of Code in Fleet Server Leading to Code Injectionelastic · kibana · CWE-94 | Critical9.1 | — | 0.5% | Aug 13, 2026 |
36Monitor | CVE-2023-46668No exploit | Elastic Endpoint Insertion of Sensitive Information into Log Fileelastic · endpoint · CWE-532 | Critical9.1 | — | 0.3% | Oct 25, 2023 |
35Monitor | CVE-2020-7009No exploit | Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create Aelastic · elasticsearch · CWE-266 | High8.8 | — | 1.6% | Mar 31, 2020 |
35Monitor | CVE-2020-7014No exploit | The fix for CVE-2020-7009 was found to be incomplete.elastic · elasticsearch · CWE-266 | High8.8 | — | 1.5% | Jun 3, 2020 |
35Monitor | CVE-2020-7018No exploit | Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.elastic · enterprise search · CWE-266 | High8.8 | — | 1.1% | Aug 18, 2020 |
35Monitor | CVE-2017-8438No exploit | Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.elastic · x-pack · CWE-284 | High8.8 | — | 1.0% | Jun 5, 2017 |
- CVE-2015-142799Now
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me
CriticalCVSS 9.8KEVWeaponizedEPSS 100%elastic · elasticsearchFeb 17, 2015
- CVE-2019-760999Now
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
CriticalCVSS 10.0KEVWeaponizedEPSS 95%elastic · kibanaMar 25, 2019
- CVE-2014-312089Now
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp
HighCVSS 8.1KEVWeaponizedEPSS 89%elastic · elasticsearchJul 28, 2014
- CVE-2018-1724664This week
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.
CriticalCVSS 9.8Proof of conceptEPSS 82%elastic · kibanaDec 20, 2018
- CVE-2021-2214549Plan
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.
MediumCVSS 6.5WeaponizedEPSS 76%elastic · elasticsearchJul 21, 2021
- CVE-2023-3141949Plan
Elasticsearch StackOverflow vulnerability
HighCVSS 7.5Proof of conceptEPSS 62%elastic · elasticsearchOct 26, 2023
- CVE-2025-2501445Plan
Kibana arbitrary code execution via prototype pollution
CriticalCVSS 9.8Proof of conceptEPSS 21%elastic · kibanaMay 6, 2025
- CVE-2015-537743Plan
Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.
CriticalCVSS 9.8Proof of conceptEPSS 14%elastic · elasticsearchMar 6, 2018
- CVE-2021-2214641Plan
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
HighCVSS 7.5Proof of conceptEPSS 36%elastic · elasticsearchJul 21, 2021
- CVE-2020-701240Plan
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.
HighCVSS 8.8WeaponizedEPSS 18%elastic · kibanaJun 3, 2020
- CVE-2019-761240Plan
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
CriticalCVSS 9.8No exploitEPSS 2%elastic · logstashMar 25, 2019
- CVE-2018-382239Monitor
X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM tr
CriticalCVSS 9.8No exploitEPSS 2%elastic · x-packMar 30, 2018
- CVE-2018-1724539Monitor
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P
CriticalCVSS 9.8No exploitEPSS 2%elastic · kibanaDec 20, 2018
- CVE-2025-2501539Monitor
Kibana arbitrary code execution via prototype pollution
CriticalCVSS 9.9No exploitEPSS 1%elastic · kibanaMar 5, 2025
- CVE-2026-3346639Monitor
Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write
CriticalCVSS 9.8No exploitEPSS 1%elastic · logstashApr 8, 2026
- CVE-2024-3728239Monitor
It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subs
CriticalCVSS 9.8No exploitEPSS 1%elastic · elastic cloud enterpriseJun 28, 2024
- CVE-2024-1255639Monitor
Kibana Prototype Pollution can lead to code injection
CriticalCVSS 9.8No exploitEPSS 1%elastic · kibanaApr 8, 2025
- CVE-2019-761037Monitor
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.
CriticalCVSS 9.0No exploitEPSS 4%elastic · kibanaMar 25, 2019
- CVE-2018-383136Monitor
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vi
HighCVSS 8.8No exploitEPSS 2%elastic · elasticsearchSep 19, 2018
- CVE-2026-7267636Monitor
Improper Control of Generation of Code in Fleet Server Leading to Code Injection
CriticalCVSS 9.1No exploitEPSS 1%elastic · kibanaAug 13, 2026
- CVE-2023-4666836Monitor
Elastic Endpoint Insertion of Sensitive Information into Log File
CriticalCVSS 9.1No exploitEPSS 0%elastic · endpointOct 25, 2023
- CVE-2020-700935Monitor
Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create A
HighCVSS 8.8No exploitEPSS 2%elastic · elasticsearchMar 31, 2020
- CVE-2020-701435Monitor
The fix for CVE-2020-7009 was found to be incomplete.
HighCVSS 8.8No exploitEPSS 2%elastic · elasticsearchJun 3, 2020
- CVE-2020-701835Monitor
Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.
HighCVSS 8.8No exploitEPSS 1%elastic · enterprise searchAug 18, 2020
- CVE-2017-843835Monitor
Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.
HighCVSS 8.8No exploitEPSS 1%elastic · x-packJun 5, 2017