Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.9) | 0.44% | — | Elasticsearch | 26/9/2026 | 6/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130) | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 1/10/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 26/9/2026 | 29/9/2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). | |
| Aplazada | Alta (8.4) | 0.27% | — | Klever-goAIElasticsearchAI | 23/9/2026 | 24/9/2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request without escaping it. The SetAccountName transaction accepts valid UTF-8 account… | |
| Aplazada | Alta (7.1) | 0.48% | — | Zlt2000 Microservices-platformAIElasticsearchAI | 16/9/2026 | 18/9/2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{indexName} and GET /agg/requestStat/{indexName}/{routing} path variables. Attackers… | |
| Aplazada | Media (6.9) | 0.83% | — | MogublogAIElasticsearchAI | 11/9/2026 | 11/9/2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete specific documents, or inject malicious… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Elastic KibanaAICriblAIElasticsearchAI | 3/9/2026 | 8/9/2026 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting in an Elasticsearch ingest pipeline being written beyond the caller's authorized… | |
| Analizada | Alta (7.1) | 0.33% | — | Elasticsearch | 1/9/2026 | 2/9/2026 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their choosing and could cause… | |
| Analizada | Media (5.9) | 0.34% | — | Elasticsearch | 1/9/2026 | 2/9/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users. | |
| Analizada | Alta (8.8) | 0.92% | — | Elasticsearch | 1/9/2026 | 2/9/2026 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader system-call surface than intended.… | |
| Analizada | Media (4.9) | 0.44% | — | Elasticsearch | 1/9/2026 | 4/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable. | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the cluster, and a size value carried inside the identifier drives an… | |
| Analizada | Media (6.5) | 0.57% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of the value being validated, so the validation causes the thread to… | |
| Analizada | Media (4.3) | 0.37% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time, degrading the availability of indexing… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation occurs outside the scope of the existing… | |
| Analizada | Media (6.5) | 0.57% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to submit a request that causes a self-referential data structure to be created. When a specific… | |
| Analizada | Media (6.5) | 0.47% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of… | |
| Analizada | Media (6.5) | 0.47% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that causes the node to attempt an excessively… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 13/8/2026 | 4/9/2026 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation allocates an unbounded amount of heap memory,… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request whose deeply nested structure is processed without a depth limit,… | |
| Analizada | Media (6.5) | 0.42% | — | Elasticsearch | 13/8/2026 | 1/9/2026 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted search request that causes an excessively large memory allocation,… |