Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted request that causes the server to construct and process a deeply nested data structure with no bound on recursion depth. Elasticsearch contains an uncontrolled recursion weakness in how it builds and serializes… | |
| Recibida | Alta (7.2) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to Privilege Escalation via a delegated administrative privilege whose scope is not fully enforced during authorization checks. Elasticsearch contains an incorrect authorization weakness in a configurable, non-default privilege that lets an administrator… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to Denial of Service via a specially crafted, deeply nested request submitted to the aggregation feature of the search API. Elasticsearch contains an uncontrolled recursion weakness in its search aggregation processing. An authenticated user with read access… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with connector management privileges could cause the cluster to allocate an uncontrolled amount of memory when connector resources with an excessively large… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to Denial of Service via Excessive Allocation (CAPEC-130). Elasticsearch enforces a size limit on the user-supplied metadata field for each individual template resource, but does not limit the total memory used when multiple such… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can allow an authenticated user with low privileges to terminate an Elasticsearch node, resulting in denial of service, via Excessive Allocation (CAPEC-130). | |
| Recibida | Media (4.3) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating… | |
| Recibida | Media (5.4) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Incorrect Authorization (CWE-863) in Elasticsearch can lead to unauthorized data stream modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user with sufficient privileges over a single resource could use the Modify Data Streams API to modify a data stream to which… | |
| Recibida | Media (6.5) | — | — | ElasticsearchAI | 6/10/2026 | 6/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can submit a specially crafted query that causes uncontrolled memory growth in the query processing engine, resulting in an out-of-memory condition that… | |
| Analizada | Media (4.9) | 0.44% | — | Elasticsearch | 26/9/2026 | 6/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 1/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Aplazada | Alta (8.4) | 0.27% | — | Klever-goAIElasticsearchAI | 23/9/2026 | 24/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account… | |
| Aplazada | Alta (7.1) | 0.48% | — | Zlt2000 Microservices-platformAIElasticsearchAI | 16/9/2026 | 18/9/2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers… | |
| Aplazada | Media (6.9) | 0.83% | — | MogublogAIElasticsearchAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Elastic KibanaAICriblAIElasticsearchAI | 3/9/2026 | 8/9/2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized… | |
| Analizada | Alta (7.1) | 0.33% | — | Elasticsearch | 1/9/2026 | 2/9/2026 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause… | |
| Analizada | Media (5.9) | 0.34% | — | Elasticsearch | 1/9/2026 | 2/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users. | |
| Analizada | Alta (8.8) | 0.92% | — | Elasticsearch | 1/9/2026 | 2/9/2026 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended.… | |
| Analizada | Media (4.9) | 0.44% | — | Elasticsearch | 1/9/2026 | 4/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable. |