Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A specially crafted request submitted by an authenticated user with minimal privileges to a validation capability of the Observability log analysis feature causes Kibana to… | |
| Analizada | Media (6.8) | 0.37% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigned to a Kibana space the requesting user has no access to, via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A user who is authorized to run Osquery… | |
| Analizada | Alta (8.1) | 0.47% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response… | |
| Analizada | Media (6.5) | 0.40% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who holds only detection rule authoring privileges for the Elastic Security solution can associate… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-case cost that grows disproportionately with the size of the input. Because the… | |
| Analizada | Media (6.5) | 0.38% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An internal Kibana data retrieval capability used by Elastic Defend endpoint response actions did not enforce the Security Solution and endpoint privileges that its… | |
| Analizada | Media (6.5) | 0.52% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A specially crafted, malformed payload submitted to a Kibana visualization feature by an authenticated user holding only low-privileged access is not correctly validated before… | |
| Analizada | Alta (7.3) | 0.18% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in… | |
| Analizada | Media (4.3) | 0.31% | — | Elastic Kibana | 13/8/2026 | 4/9/2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-915) in the case management functionality of Elastic Security in Kibana can lead to unauthorized modification of case data by an authenticated user who has not been granted case editing privileges, via Manipulating User-Controlled… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user who is authorized to manage maintenance windows could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with read-only privileges to the alerting feature could submit a specially crafted, malformed payload that causes the Kibana process to consume excessive… | |
| Analizada | Media (4.3) | 0.34% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user who is authorized to read alerting rules in a single Kibana space could retrieve alerting rule execution telemetry that… | |
| Analizada | Alta (7.1) | 0.38% | — | Elastic Kibana | 13/8/2026 | 3/9/2026 | Kibana Agent Builder determines whether a caller owns a private agent by comparing a stable user identifier when one is recorded, and falling back to a comparison of the username when it is not. A username is not unique across Elasticsearch authentication realms, so two distinct principals that share a username in… | |
| Analizada | Alta (7.1) | 0.35% | — | Elastic Kibana | 13/8/2026 | 3/9/2026 | Observable Discrepancy (CWE-203) in Kibana Fleet can lead to information disclosure via Excavation (CAPEC-116). Fleet removes the Elasticsearch API key value of an enrolled Elastic Agent from the responses of its agent listing capability, but that capability accepted caller-supplied filter expressions over the stored… | |
| Analizada | Media (6.5) | 0.33% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to Elastic Agents enrolled in the… | |
| Analizada | Alta (7.1) | 0.31% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration… | |
| Analizada | Alta (7.1) | 0.42% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read,… | |
| Analizada | Baja (3.5) | 0.29% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 13/8/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A query expression accepted by a connector reporting operation was processed without any limit on its size, and an oversized expression caused the Kibana process to spend an… | |
| Aplazada | Alta (8.7) | 0.51% | — | Budibase ServerAI | 13/8/2026 | 31/8/2026 | Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to… | |
| Aplazada | Alta (7.1) | 0.34% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are enriched with handlebars using noEscaping: true and parsed without operator filtering. Attackers can inject MongoDB operators through query parameters to bypass per-user access… | |
| Aplazada | Media (5.1) | 0.32% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through /api/datasources/verify and distinguish… | |
| Aplazada | Crítica (9) | 0.54% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the datasource origin. An unauthenticated caller of a PUBLIC POST… | |
| Aplazada | Alta (7.5) | 0.51% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users… |