Elastic

First CVE: Jun 5, 2017Active for: 9 years
264
CVEs Published
More CVEs Published than 82% of tracked CNAs
26.4
Avg CVEs / Year
More Avg CVEs / Year than 74% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked CNAs
0.4%
In CISA KEV
Higher KEV Rate than 83% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Elastic as a CNA, 93.9% affect products that Elastic develops as a vendor.

93.9%
Self-reported: 248Third-party: 16

Of all the CVEs published that affect products developed by Elastic, 93.9% are self-published by Elastic as a CNA.

93.9%
Self-published: 248Published by other CNAs: 16

Trends Over Time

The number and severity of CVEs published by Elastic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 5, 2017
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Elastic as a CNA, regardless of affected vendor or product.

264 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a reques
Mar 25, 201910.098YESYES
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submi
Jul 21, 20216.586NOYES
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that
Dec 20, 20189.883NOYES
A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.
Oct 26, 20237.557NONO
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters. While in the default setting the anonymous user has no perm
Jul 21, 20217.550NOYES
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana inde
Jun 3, 20208.840NOYES
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
May 6, 20259.839NONO
Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input
Jul 1, 20268.037NONO
Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can submit a specia
Jul 1, 20267.533NONO
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to arbitrary file write and potentially remote code execution via Relative Path Traversal
Apr 8, 20269.833NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA264 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local17 (6.4%)
Network236 (89.4%)
Unknown0 (0.0%)
Physical1 (0.4%)
Adjacent Network10 (3.8%)
Attack Complexity
Low238 (90.2%)
High26 (9.8%)
Unknown0 (0.0%)
User Interaction
None220 (83.3%)
Unknown0 (0.0%)
Required44 (16.7%)
Privileges Required
Low153 (58.0%)
High17 (6.4%)
None94 (35.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (264 CVEs).

CISA KEV
1 CVE
0.4% of CVEs· 83rd percentile
Metasploit
3 CVEs
1.1% of CVEs· 87th percentile
Nuclei
3 CVEs
1.1% of CVEs· 81st percentile
ExploitDB
2 CVEs
0.8% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Elastic as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Elastic as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs