İçeriğe atla
Noroxi

Elastic kayıtları

elastic üreticisine ait 349 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
3 · %0,9
Silahlaştırılmış
5 · %1,4
Pre-auth RCE
11
Düzeltme kaydı olan
%30,1
Yayından KEV’e ortanca
2593 gün

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

349 kayıt
  • The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection me

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    elastic · elasticsearch17 Şub 2015

  • Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %95

    elastic · kibana25 Mar 2019

  • The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL exp

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %89

    elastic · elasticsearch28 Tem 2014

  • CVE-2018-17246
    64Bu hafta

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin.

    KritikCVSS 9,8Kavram kanıtıEPSS %82

    elastic · kibana20 Ara 2018

  • CVE-2021-22145
    49Planlayın

    A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting.

    OrtaCVSS 6,5SilahlaştırılmışEPSS %76

    elastic · elasticsearch21 Tem 2021

  • CVE-2023-31419
    49Planlayın

    Elasticsearch StackOverflow vulnerability

    YüksekCVSS 7,5Kavram kanıtıEPSS %62

    elastic · elasticsearch26 Eki 2023

  • CVE-2025-25014
    45Planlayın

    Kibana arbitrary code execution via prototype pollution

    KritikCVSS 9,8Kavram kanıtıEPSS %21

    elastic · kibana6 May 2025

  • CVE-2015-5377
    43Planlayın

    Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol.

    KritikCVSS 9,8Kavram kanıtıEPSS %14

    elastic · elasticsearch6 Mar 2018

  • CVE-2021-22146
    41Planlayın

    All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.

    YüksekCVSS 7,5Kavram kanıtıEPSS %36

    elastic · elasticsearch21 Tem 2021

  • CVE-2020-7012
    40Planlayın

    Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant.

    YüksekCVSS 8,8SilahlaştırılmışEPSS %18

    elastic · kibana3 Haz 2020

  • CVE-2019-7612
    40Planlayın

    A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.

    KritikCVSS 9,8İstismar yokEPSS %2

    elastic · logstash25 Mar 2019

  • CVE-2018-3822
    39İzleyin

    X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM tr

    KritikCVSS 9,8İstismar yokEPSS %2

    elastic · x-pack30 Mar 2018

  • CVE-2018-17245
    39İzleyin

    Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P

    KritikCVSS 9,8İstismar yokEPSS %2

    elastic · kibana20 Ara 2018

  • CVE-2025-25015
    39İzleyin

    Kibana arbitrary code execution via prototype pollution

    KritikCVSS 9,9İstismar yokEPSS %1

    elastic · kibana5 Mar 2025

  • CVE-2026-33466
    39İzleyin

    Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write

    KritikCVSS 9,8İstismar yokEPSS %1

    elastic · logstash8 Nis 2026

  • CVE-2024-37282
    39İzleyin

    It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subs

    KritikCVSS 9,8İstismar yokEPSS %1

    elastic · elastic cloud enterprise28 Haz 2024

  • CVE-2024-12556
    39İzleyin

    Kibana Prototype Pollution can lead to code injection

    KritikCVSS 9,8İstismar yokEPSS %1

    elastic · kibana8 Nis 2025

  • CVE-2019-7610
    37İzleyin

    Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger.

    KritikCVSS 9,0İstismar yokEPSS %4

    elastic · kibana25 Mar 2019

  • CVE-2018-3831
    36İzleyin

    Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured vi

    YüksekCVSS 8,8İstismar yokEPSS %2

    elastic · elasticsearch19 Eyl 2018

  • CVE-2026-72676
    36İzleyin

    Improper Control of Generation of Code in Fleet Server Leading to Code Injection

    KritikCVSS 9,1İstismar yokEPSS %1

    elastic · kibana13 Ağu 2026

  • CVE-2023-46668
    36İzleyin

    Elastic Endpoint Insertion of Sensitive Information into Log File

    KritikCVSS 9,1İstismar yokEPSS %0

    elastic · endpoint25 Eki 2023

  • CVE-2020-7009
    35İzleyin

    Elasticsearch versions from 6.7.0 before 6.8.8 and 7.0.0 before 7.6.2 contain a privilege escalation flaw if an attacker is able to create A

    YüksekCVSS 8,8İstismar yokEPSS %2

    elastic · elasticsearch31 Mar 2020

  • CVE-2020-7014
    35İzleyin

    The fix for CVE-2020-7009 was found to be incomplete.

    YüksekCVSS 8,8İstismar yokEPSS %2

    elastic · elasticsearch3 Haz 2020

  • CVE-2020-7018
    35İzleyin

    Elastic Enterprise Search before 7.9.0 contain a credential exposure flaw in the App Search interface.

    YüksekCVSS 8,8İstismar yokEPSS %1

    elastic · enterprise search18 Ağu 2020

  • CVE-2017-8438
    35İzleyin

    Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality.

    YüksekCVSS 8,8İstismar yokEPSS %1

    elastic · x-pack5 Haz 2017