50 exploited vulnerabilities in Elasticsearch
- Vendors
- Budibase, Apache, Amazon, Elastic, Mongodb, Unknown
- With known exploits
- 50
- Affected Budibase versions
- < 3.39.12
- Affected Elastic Elasticsearch versions
- < 1.6.1, 1.3.8, 1.4.3, 1.2.0, 7.17.24, 8.15.1, 8.2.1, 7.17.25, 8.16.0, 7.17.29, 8.19.8, 9.1.8, 9.2.2, 7.17.12, 8.9.0, 8.15.0, 8.19.9, 9.1.9, 9.2.3, 7.13.3, 7.17.16, 8.11.2
- Affected Icinga versions
- < 2.11.10, 2.12.5
- Affected Vmware Spring Ai versions
- < 1.0.9, 1.1.8
- Affected Nagios Log Server versions
- < 2024
- Affected Apereo Opencast versions
- < 13.10, 14.3, 16.7
- Affected Elastic Kibana versions
- < 8.19.16, 9.3.5, 9.4.2
- Affected Mattermost Mattermost Server versions
- < 9.5.10
Vulnerabilities with exploits
Highest CVSS first β 8 of these already have exploit code on Sploitus
CVE-2026-54350 1 exploit
CVE-2025-35434
CVE-2015-5377 2 exploits
Exploit for Injection in Elastic ElasticsearchApache Groovy Deserialization of Untrusted Data Remote Code Execution Exploit 0day
CVE-2015-1427 21 exploits
CVE-2025-12977
CVE-2021-32743
CVE-2026-47835
CVE-2025-44824
CVE-2014-3120 16 exploits
Exploit for Improper Access Control in ElasticsearchExploit for Improper Access Control in Elasticsearch
CVE-2024-52981
CVE-2024-43709
CVE-2023-31418
CVE-2022-23712
CVE-2024-52979
CVE-2024-52797
CVE-2024-23444
CVE-2024-23450
CVE-2022-42123
CVE-2025-37731
CVE-2024-23445
CVE-2023-31419 4 exploits
CVE-2026-35211
CVE-2026-56148
CVE-2026-49090
CVE-2026-49095
CVE-2025-68384
CVE-2024-52980
CVE-2024-12539
CVE-2024-7610
CVE-2024-23451
CVE-2023-46673
CVE-2021-22145 5 exploits
CVE-2023-46674
CVE-2026-5417
CVE-2025-37727
CVE-2025-12978
CVE-2024-32037
CVE-2024-10241
CVE-2024-23449
CVE-2023-49921
CVE-2015-5531 7 exploits
CVE-2026-56149
CVE-2025-68390
CVE-2024-39810
CVE-2024-37280
CVE-2024-52032
CVE-2022-38299
CVE-2022-23708
CVE-2015-3337 4 exploits
ElasticSearch 1.4.5 / 1.5.2 - Path Transversal VulnerabilityElasticSearch 1.4.5 1.5.2 - Directory Traversal
CVE-2023-31417