Vulnerabilities (CVE)

Total 397891 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25017 1 Elastic 1 Kibana 2026-06-17 N/A 8.2 HIGH
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)
CVE-2025-25016 1 Elastic 1 Kibana 2026-06-17 N/A 4.3 MEDIUM
Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.
CVE-2025-25015 1 Elastic 1 Kibana 2026-06-17 N/A 9.9 CRITICAL
Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors
CVE-2025-25014 1 Elastic 1 Kibana 2026-06-17 N/A 9.1 CRITICAL
A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
CVE-2025-25013 2026-06-17 N/A 6.5 MEDIUM
Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.
CVE-2025-25012 1 Elastic 1 Kibana 2026-06-17 N/A 4.3 MEDIUM
URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.
CVE-2025-25011 2026-06-17 N/A 7.0 HIGH
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.
CVE-2025-25010 1 Elastic 1 Kibana 2026-06-17 N/A 6.5 MEDIUM
Incorrect authorization in Kibana can lead to privilege escalation via the built-in reporting_user role which incorrectly has the ability to access all Kibana Spaces.
CVE-2025-25009 1 Elastic 1 Kibana 2026-06-17 N/A 8.7 HIGH
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
CVE-2025-25008 1 Microsoft 5 Windows Server 2016, Windows Server 2019, Windows Server 2022 and 2 more 2026-06-17 N/A 7.1 HIGH
Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
CVE-2025-25007 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-06-17 N/A 5.3 MEDIUM
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-25006 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-06-17 N/A 5.3 MEDIUM
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-25005 1 Microsoft 2 Exchange Server, Exchange Server Subscription Edition 2026-06-17 N/A 6.5 MEDIUM
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
CVE-2025-25004 1 Microsoft 17 Powershell, Windows 10 1507, Windows 10 1607 and 14 more 2026-06-17 N/A 7.3 HIGH
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2025-25003 1 Microsoft 2 Visual Studio 2019, Visual Studio 2022 2026-06-17 N/A 7.3 HIGH
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.
CVE-2025-25002 1 Microsoft 1 Azure Local Cluster 2026-06-17 N/A 6.8 MEDIUM
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.
CVE-2025-25001 1 Microsoft 1 Edge 2026-06-17 N/A 4.3 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-25000 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 8.8 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2025-24999 1 Microsoft 4 Sql Server 2016, Sql Server 2017, Sql Server 2019 and 1 more 2026-06-17 N/A 8.8 HIGH
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-24998 1 Microsoft 3 Visual Studio 2017, Visual Studio 2019, Visual Studio 2022 2026-06-17 N/A 7.3 HIGH
Uncontrolled search path element in Visual Studio allows an authorized attacker to elevate privileges locally.