|
721
|
- |
|
-
|
-
|
A stored cross-site scripting (XSS) vulnerability exists in the notification panel of CTI Transmute in versions prior to the patched release. Notification messages containing user-controlled convert …
|
CWE-79
Cross-site Scripting
|
CVE-2026-9806
|
2026-05-29 23:46 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
722
|
- |
|
-
|
-
|
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9813
|
2026-05-29 23:46 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
723
|
4.6 |
MEDIUM
Network
|
-
|
-
|
A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifi…
|
CWE-22
Path Traversal
|
CVE-2026-33462
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
724
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-b…
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-33463
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
725
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-33464
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
726
|
4.1 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42401
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
727
|
7.7 |
HIGH
Network
|
-
|
-
|
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connec…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42398
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
728
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can cause Kibana to consume exponentiall…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42399
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
729
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user can send a specially crafted compressed request payload…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42400
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
730
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server t…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49093
|
2026-05-29 23:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|