| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-0530 | Allocation of Resources Without Limits or Throttling in Kibana Leading to Excessive Allocation | Elastic | Kibana | Medium | 6.5 | 2026-01-13 21:03:14 | Deep Dive |
| CVE-2026-0528 | Improper Input Validation in Metricbeat Leading to Denial of Service | Elastic | Metricbeat | Medium | 6.5 | 2026-01-13 21:02:19 | Deep Dive |
| CVE-2025-68422 | Kibana Improper Authorization | Elastic | Kibana | Medium | 4.3 | 2025-12-18 22:32:17 | Deep Dive |
| CVE-2025-68386 | Kibana Improper Authorization | Elastic | Kibana | Medium | 4.3 | 2025-12-18 22:21:09 | Deep Dive |
| CVE-2025-68390 | Elasticsearch Allocation of Resources Without Limits or Throttling | Elastic | Elasticsearch | Medium | 4.9 | 2025-12-18 22:17:42 | Deep Dive |
| CVE-2025-68389 | Kibana Allocation of Resources Without Limits or Throttling | Elastic | Kibana | Medium | 6.5 | 2025-12-18 22:14:52 | Deep Dive |
| CVE-2025-68387 | Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Elastic | Kibana | Medium | 6.1 | 2025-12-18 22:11:39 | Deep Dive |
| CVE-2025-68385 | Kibana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Elastic | Kibana | High | 7.2 | 2025-12-18 22:08:38 | Deep Dive |
| CVE-2025-68384 | Elasticsearch Allocation of Resources Without Limits or Throttling | Elastic | Elasticsearch | Medium | 6.5 | 2025-12-18 22:04:50 | Deep Dive |
| CVE-2025-68383 | Filebeat Improper Validation of Specified Index, Position, or Offset in Input | Elastic | Filebeat | Medium | 6.5 | 2025-12-18 22:00:12 | Deep Dive |
| CVE-2025-68382 | Packetbeat Out-of-bounds Read | Elastic | Packetbeat | Medium | 6.5 | 2025-12-18 21:56:03 | Deep Dive |
| CVE-2025-68381 | Packetbeat Improper Bounds Check | Elastic | Packetbeat | Medium | 6.5 | 2025-12-18 21:51:36 | Deep Dive |
| CVE-2025-68388 | Elastic Packetbeat 安全漏洞 | Elastic | Packetbeat | Medium | 5.3 | 2025-12-18 21:33:51 | Deep Dive |
| CVE-2025-37731 | Elasticsearch Improper Authentication | Elastic | Elasticsearch | Medium | 6.8 | 2025-12-15 10:42:22 | Deep Dive |
| CVE-2025-37732 | Kibana Cross-site Scripting via the Integration Package Upload Functionality | Elastic | Kibana | Medium | 5.4 | 2025-12-15 10:21:08 | Deep Dive |
| CVE-2025-66525 | WordPress Elastic Email Sender plugin <= 1.2.20 - Broken Access Control vulnerability | Elastic Email | Elastic Email Sender | Medium | 4.3 | 2025-12-09 14:13:53 | Deep Dive |
| CVE-2025-37734 | Kibana Origin Validation Error | Elastic | Kibana | Medium | 4.3 | 2025-11-12 09:57:23 | Deep Dive |
| CVE-2025-12637 | Elastic Theme Editor <= 0.0.3 - Authenticated (Subscriber+) Arbitrary File Upload | koopersmith | Elastic Theme Editor | High | 8.8 | 2025-11-11 03:30:50 | Deep Dive |
| CVE-2025-37736 | Elastic Cloud Enterprise Improper Authorization | Elastic | Elastic Cloud Enterprise (ECE) | High | 8.8 | 2025-11-07 22:08:12 | Deep Dive |
| CVE-2025-37735 | Elastic Defend 安全漏洞 | Elastic | Kibana | High | 7.0 | 2025-11-06 14:27:26 | Deep Dive |