Перейти к содержимому
Noroxi

Записи Elastic

349 опубликованных записей вендора elastic.

Профиль для исследователя

Попали в KEV
3 · 0,9 %
С эксплойтом
5 · 1,4 %
Pre-auth RCE
11
С записью об исправлении
30,1 %
Медиана: публикация → KEV
2593 дн.

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

349 записей
  • CVE-2015-1427
    99Срочно

    The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    elastic · elasticsearch17 февр. 2015 г.

  • CVE-2019-7609
    99Срочно

    Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %

    elastic · kibana25 мар. 2019 г.

  • CVE-2014-3120
    89Срочно

    The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 89 %

    elastic · elasticsearch28 июл. 2014 г.

  • CVE-2018-17246
    64На этой неделе

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.

    КритическаяCVSS 9,8Proof of conceptEPSS 82 %

    elastic · kibana20 дек. 2018 г.

  • CVE-2021-22145
    49В плане

    A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.

    СредняяCVSS 6,5Готовый эксплойтEPSS 76 %

    elastic · elasticsearch21 июл. 2021 г.

  • CVE-2023-31419
    49В плане

    Elasticsearch StackOverflow vulnerability

    ВысокаяCVSS 7,5Proof of conceptEPSS 62 %

    elastic · elasticsearch26 окт. 2023 г.

  • CVE-2025-25014
    45В плане

    Kibana arbitrary code execution via prototype pollution

    КритическаяCVSS 9,8Proof of conceptEPSS 21 %

    elastic · kibana6 мая 2025 г.

  • CVE-2015-5377
    43В плане

    Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.

    КритическаяCVSS 9,8Proof of conceptEPSS 14 %

    elastic · elasticsearch6 мар. 2018 г.

  • CVE-2021-22146
    41В плане

    All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.

    ВысокаяCVSS 7,5Proof of conceptEPSS 36 %

    elastic · elasticsearch21 июл. 2021 г.

  • CVE-2020-7012
    40В плане

    Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 18 %

    elastic · kibana3 июн. 2020 г.

  • CVE-2019-7612
    40В плане

    A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    elastic · logstash25 мар. 2019 г.

  • CVE-2018-3822
    39Наблюдать

    X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM tr

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    elastic · x-pack30 мар. 2018 г.

  • CVE-2018-17245
    39Наблюдать

    Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    elastic · kibana20 дек. 2018 г.

  • CVE-2025-25015
    39Наблюдать

    Kibana arbitrary code execution via prototype pollution

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    elastic · kibana5 мар. 2025 г.

  • CVE-2026-33466
    39Наблюдать

    Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    elastic · logstash8 апр. 2026 г.

  • CVE-2024-37282
    39Наблюдать

    It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subs

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    elastic · elastic cloud enterprise28 июн. 2024 г.

  • CVE-2024-12556
    39Наблюдать

    Kibana Prototype Pollution can lead to code injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    elastic · kibana8 апр. 2025 г.

  • CVE-2019-7610
    37Наблюдать

    Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.

    КритическаяCVSS 9,0Эксплойта нетEPSS 4 %

    elastic · kibana25 мар. 2019 г.

  • CVE-2018-3831
    36Наблюдать

    Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    elastic · elasticsearch19 сент. 2018 г.

  • CVE-2026-72676
    36Наблюдать

    Improper Control of Generation of Code in Fleet Server Leading to Code Injection

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    elastic · kibana13 авг. 2026 г.

  • CVE-2023-46668
    36Наблюдать

    Elastic Endpoint Insertion of Sensitive Information into Log File

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    elastic · endpoint25 окт. 2023 г.

  • CVE-2020-7009
    35Наблюдать

    Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create A

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    elastic · elasticsearch31 мар. 2020 г.

  • CVE-2020-7014
    35Наблюдать

    The fix for CVE-2020-7009 was found to be incomplete.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    elastic · elasticsearch3 июн. 2020 г.

  • CVE-2020-7018
    35Наблюдать

    Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    elastic · enterprise search18 авг. 2020 г.

  • CVE-2017-8438
    35Наблюдать

    Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    elastic · x-pack5 июн. 2017 г.