Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
47882
Total
3850
Critical
14243
High
13921
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-72651 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only … | Aug 13, 2026 |
| CVE-2026-72650 | MEDIUM | 4.3 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user … | Aug 13, 2026 |
| CVE-2026-72648 | MEDIUM | 6.5 | Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can lead to information disclosure via Retrieve Embedded Sensitive … | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges … | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read … | Aug 13, 2026 |
| CVE-2026-72643 | HIGH | 7.1 | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to … | Aug 13, 2026 |
| CVE-2026-72642 | HIGH | 8.8 | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset … | Aug 13, 2026 |
| CVE-2026-72640 | MEDIUM | 6.5 | The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manages, and it accepts the namespace … | Aug 13, 2026 |
| CVE-2026-72639 | MEDIUM | 6.5 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is … | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions … | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve … | Aug 13, 2026 |
| CVE-2026-72632 | HIGH | 7.1 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic … | Aug 13, 2026 |
| CVE-2026-72631 | MEDIUM | 6.5 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams … | Aug 13, 2026 |
| CVE-2026-72630 | HIGH | 7.1 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one … | Aug 13, 2026 |
| CVE-2026-72629 | HIGH | 7.1 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result … | Aug 13, 2026 |
| CVE-2026-59714 | HIGH | 7.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 before 0.10.0, any authenticated user can overwrite the content of a message … | Aug 13, 2026 |
| CVE-2026-49864 | UNKNOWN | — | wetty provides terminal access in browser over http/https. Prior to version 3.0.4, the wetty client decodes a base64 filename from the file-download escape sequence and … | Aug 13, 2026 |
| CVE-2026-49096 | MEDIUM | 4.3 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment … | Aug 13, 2026 |
| CVE-2026-49089 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by … | Aug 13, 2026 |
| CVE-2026-48099 | HIGH | 7.1 | WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent-directory … | Aug 13, 2026 |
| CVE-2026-45774 | UNKNOWN | — | compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs … | Aug 13, 2026 |
| CVE-2026-45725 | UNKNOWN | — | compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and … | Aug 13, 2026 |
| CVE-2026-19747 | CRITICAL | 9.8 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the … | Aug 13, 2026 |
| CVE-2026-19746 | MEDIUM | 4.3 | A vulnerability has been found in Calix GigaSpire 26.1.0. The affected element is an unknown function of the file traceroute.cmd. The manipulation leads to denial … | Aug 13, 2026 |
| CVE-2026-19745 | MEDIUM | 4.3 | A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknown function of the file utilities_configurationsave.cgi of the component Web Management Interface. Executing … | Aug 13, 2026 |