Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-09-01
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing access to and modification of data beyond their own authorization scope.
CVSS Score
8.3
EPSS Score
0.003
Published
2026-09-01
Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the user is not authorized to read.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-09-01
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.
CVSS Score
4.9
EPSS Score
0.003
Published
2026-09-01
Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-09-01
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
CVSS Score
9.6
EPSS Score
0.003
Published
2026-09-01
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
CVSS Score
7.5
EPSS Score
0.003
Published
2026-09-01
llama.cpp b5693 and before is vulnerable to Uncontrolled Recursion in common/json-schema-to-grammar.cpp, resulting in a denial of service.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-09-01
llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-09-01
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-09-01


Contact Us

Shodan ® - All rights reserved