Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-73531 — django-helpdesk < 2.3.3 Stored XSS via HTML Attachments

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by submitting HTML-formatted email messages or u…

Remote | Cross-Site Scripting
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.7 HIGH
CVE-2026-73530 — Flyto2 Core < 2.28.0 SSRF Guard Bypass via is_private_ip()

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by supplying URLs using the unblocked IPv6 address `::` wh…

Remote | Server-Side Request Forgery
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72687 — Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72686 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recur…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-72685 — Inefficient Algorithmic Complexity in Elasticsearch Leading to Denial of Service

A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occ…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72684 — Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial o…

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific in…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72683 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-i…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72681 — Missing Authorization in Kibana Leading to Privilege Escalation and Information Disclosure

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates and runs a tool that invokes that feature's functi…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72680 — Authorization Bypass Through User-Controlled Key in Kibana Agent Builder Leading to Unaut…

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on that identifier does not distinguish between a co…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72679 — Uncontrolled Recursion in Elasticsearch Leading to Denial of Service

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exh…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72678 — Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service

Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privi…

elasticsearch | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.3 HIGH
CVE-2026-72677 — Relative Path Traversal in Kibana Fleet Leading to Unauthorized Deletion of Users and Oth…

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana Fleet accepted a user-supplied identifier for a Fl…

kibana | Remote | Path Traversal
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72676 — Improper Control of Generation of Code in Fleet Server Leading to Code Injection

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an ide…

fleet_server | Remote | Injection
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.1 HIGH
CVE-2026-72675 — Missing Authorization in Kibana Machine Learning Leading to Cross-Space Information Discl…

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPEC-122). Kibana Machine Learning carries out its El…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
6.5 MEDIUM
CVE-2026-72674 — Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Servi…

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user-supplied list of document fields accepted by the …

kibana | Remote | Denial of Service
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
5.4 MEDIUM
CVE-2026-72673 — Incorrect Authorization in Kibana Leading to Unauthorized Deletion of Synthetics Private …

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Synthetics privat…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.7 HIGH
CVE-2026-72672 — Incorrect Authorization in Kibana Leading to Disclosure of Elastic Defend Endpoint Event …

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data with Kibana's internal Elasticsearch account inste…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
4.3 MEDIUM
CVE-2026-72671 — Missing Authorization in Kibana Leading to Unauthorized Modification of Machine Learning …

A Kibana Machine Learning capability that removes a saved object from the current space accepts machine learning trained models as a target, but it verifies only the privileges that apply to anomaly …

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.7 HIGH
CVE-2026-72670 — Exposure of Sensitive Information to an Unauthorized Actor in Kibana Leading to Disclosur…

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would normally require the Fleet privilege to read sett…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
7.6 HIGH
CVE-2026-72669 — Missing Authorization in Kibana Leading to Cross-User Information Disclosure and Data Tam…

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update that state do not verify ownership. An authenticat…

kibana | Remote | Authorization
Aug 13, 2026 Aug 13, 2026
Aug 13, 2026
Aug 13, 2026
Showing 20 of 10656 Results