Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Elastic — Vulnerabilities & Security Advisories 309

Browse all 309 CVE security advisories affecting Elastic. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Elastic operates as a search and analytics engine, primarily powering the ELK Stack for log management and data visualization. With 223 recorded Common Vulnerabilities and Exposures, the platform has historically been susceptible to critical flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from improper input validation and authentication bypasses within its Java-based architecture. Notable incidents involve unauthorized access to sensitive data through exposed APIs, highlighting risks associated with default configurations. The sheer volume of CVEs suggests persistent challenges in securing complex distributed systems. While the software remains a cornerstone for enterprise search, its extensive attack surface requires rigorous patching and strict access controls to mitigate the high probability of exploitation by threat actors targeting its widespread deployment infrastructure.

Found 153 results / 309 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-25016 Kibana Unrestricted Upload of File — Kibana CWE-434 4.3 Medium 2025-05-01
CVE-2024-12556 Kibana Prototype Pollution can lead to code injection — Kibana CWE-1321 8.7 High 2025-04-08
CVE-2024-52974 Elastic Kibana 资源管理错误漏洞 — Kibana CWE-400 6.5 Medium 2025-04-08
CVE-2025-25015 Kibana arbitrary code execution via prototype pollution — Kibana CWE-1321 9.9 Critical 2025-03-05
CVE-2024-43708 Elastic Kibana 安全漏洞 — Kibana CWE-770 6.5 Medium 2025-01-23
CVE-2024-52972 Kibana allocation of resources without limits or throttling leads to crash — Kibana CWE-770 6.5 Medium 2025-01-23
CVE-2024-43707 Kibana exposure of sensitive information to an unauthorized actor — Kibana CWE-200 7.7 High 2025-01-23
CVE-2024-43710 Kibana server-side request forgery — Kibana CWE-918 4.3 Medium 2025-01-23
CVE-2024-52973 Kibana allocation of resources without limits or throttling leads to crash — Kibana CWE-770 6.5 Medium 2025-01-21
CVE-2024-37285 Kibana arbitrary code execution via YAML deserialization — Kibana CWE-502 9.1 Critical 2024-11-14
CVE-2024-37288 Elastic Kibana 安全漏洞 — Kibana CWE-502 9.9 Critical 2024-09-09
CVE-2024-37287 Kibana arbitrary code execution via prototype pollution — Kibana CWE-94 9.1 Critical 2024-08-13
CVE-2024-37281 Kibana Denial of Service issue — Kibana CWE-400 6.5 Medium 2024-07-30
CVE-2024-23443 Elastic Kibana 安全漏洞 — Kibana CWE-400 4.9 Medium 2024-06-19
CVE-2024-23442 Kibana open redirect issue — Kibana CWE-601 6.1 Medium 2024-06-14
CVE-2024-37279 Kibana Broken Access Control issue — Kibana 4.3 Medium 2024-06-13
CVE-2024-23446 Kibana Broken Access Control issue — Kibana CWE-284 6.5 Medium 2024-02-07
CVE-2023-46675 Kibana Insertion of Sensitive Information into Log File — Kibana CWE-532 8.0 High 2023-12-13
CVE-2023-46671 Kibana Insertion of Sensitive Information into Log File — Kibana CWE-532 8.0 High 2023-12-13
CVE-2021-22142 Kibana Reporting vulnerabilities — Kibana CWE-1104 6.6 Medium 2023-11-22
CVE-2021-22151 Kibana path traversal issue — Kibana CWE-22 3.1 Low 2023-11-22
CVE-2021-22150 Kibana code execution issue — Kibana CWE-94 6.6 Medium 2023-11-22
CVE-2023-31422 Kibana Insertion of Sensitive Information into Log File — Kibana CWE-532 9.0 Critical 2023-10-26
CVE-2023-31415 Elastic Kibana 代码注入漏洞 — Kibana CWE-94 9.9 - 2023-05-04
CVE-2023-31414 Elastic Kibana 代码注入漏洞 — Kibana CWE-94 9.1 - 2023-05-04
CVE-2022-38779 Elastic Kibana 输入验证错误漏洞 — kibana CWE-601 6.1 - 2023-02-21
CVE-2022-38778 Kibana 输入验证错误漏洞 — kibana CWE-20 6.5 - 2023-02-08
CVE-2021-22141 Elastic Kibana 输入验证错误漏洞 — Kibana CWE-601 6.1 - 2022-11-18
CVE-2021-37936 Elastic Kibana 跨站脚本漏洞 — Kibana CWE-79 6.1 - 2022-11-18
CVE-2022-23713 Vega 跨站脚本漏洞 — kibana CWE-79 6.1 - 2022-07-06

This page lists every published CVE security advisory associated with Elastic. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.