Vulnerabilities (CVE)

Filtered by vendor Elastic Subscribe
Total 342 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-4326 1 Elastic 1 Logstash 2026-06-17 7.5 HIGH N/A
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.
CVE-2014-3120 1 Elastic 1 Elasticsearch 2026-06-17 6.8 MEDIUM 8.1 HIGH
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.