floragunn
CVE Numbering Authority
Latest CVE published
Overview
floragunn is a CVE Numbering Authority that has published 13 CVE records since 2019. It is currently classified as active, with 4 CVEs published in the last two years. Its CVE data quality is graded B (82.7% overall completeness).
Among the 370 CNAs tracked here, floragunn ranks #278 by CVE volume and reports more complete records than 31% of all CNAs.
Data quality report card
How complete and consistent floragunn's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often floragunn also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
82.7%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of floragunn's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of floragunn's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
Common weakness types
The CWE weakness categories floragunn most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-200Exposure of Sensitive Information to an Unauthorized Actor3 CVEs
- CWE-311Missing Encryption of Sensitive Data2 CVEs
- CWE-285Improper Authorization2 CVEs
- CWE-287Improper Authentication1 CVE
- CWE-522Insufficiently Protected Credentials1 CVE
- CWE-532Insertion of Sensitive Information into Log File1 CVE
- CWE-601URL Redirection to Untrusted Site ('Open Redirect')1 CVE
- CWE-732Incorrect Permission Assignment for Critical Resource1 CVE
Publishing activity by year
How many CVEs floragunn has published each year.
Top vendors
The vendors floragunn publishes the most CVEs for.
- floragunn16 CVEs
- search-guard12 CVEs
- floragunncom2 CVEs
Top products
The products floragunn publishes the most CVEs for.
- Search Guard9 CVEs
- Search Guard FLX7 CVEs
- flx3 CVEs
- Search Guard Kibana Plugin2 CVEs
- search-guard-kibana-plugin2 CVEs
Latest CVEs
The most recent CVEs assigned by floragunn.
- CVE-2026-4819CWE-532
Search Guard audit logs can contain under certain conditions user credentials
Medium · CVSS 6.5EPSS 0.2%2026-03-31 - CVE-2026-4818CWE-285
Some management operations on data streams are not properly restricted when user does not have the necessary privileges
High · CVSS 8.1EPSS 0.2%2026-03-31 - CVE-2026-4799CWE-601
Open redirect vulnerability in Search Guard Kibana Plugin via manipulated requests
Medium · CVSS 4.3EPSS 0.2%2026-03-31 - CVE-2025-13653CWE-200
Unauthorized access to documents in data streams with specially crafted requests
Medium · CVSS 4.3EPSS 0.2%2025-12-01 - CVE-2025-12149CWE-200
Unauthorized access to documents protected by Document-Level Security (DLS), when Signals watches include a search query involving protected documents
Medium · CVSS 6.0EPSS 0.3%2025-11-14 - CVE-2025-12148CWE-200
Unauthorized access to fields protected by Field Masking (FM) for fields of type IP
Medium · CVSS 6.0EPSS 0.3%2025-10-29 - CVE-2025-12147CWE-732
Unauthorized access to fields protected by Field-Level Security (FLS) when those fields are members of an object
Medium · CVSS 6.0EPSS 0.3%2025-10-29 - CVE-2019-13422CWE-79Medium · CVSS 6.1EPSS 0.9%2019-08-23
- CVE-2019-13423CWE-287High · CVSS 8.8EPSS 0.7%2019-08-23
- CVE-2019-13421CWE-522Medium · CVSS 4.9EPSS 1.1%2019-08-23
- CVE-2019-13415CWE-280Medium · CVSS 6.5EPSS 1.0%2019-08-13
- CVE-2019-13416CWE-285Medium · CVSS 6.5EPSS 1.0%2019-08-13
Track new floragunn CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor floragunn CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the floragunn CNA.
- What is the floragunn CNA?
- floragunn is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 13 CVE records since 2019.
- How many CVEs has floragunn published?
- floragunn has published 13 CVE records, including 4 in the last two years.
- What is floragunn's CVE data quality grade?
- RadicalNotion.AI grades floragunn's CVE data quality as B, with an overall completeness score of 82.7%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (30.8%), and CWE (100%) information.
- What products does floragunn publish CVEs for?
- floragunn most frequently publishes CVEs for Search Guard, Search Guard FLX, flx, Search Guard Kibana Plugin, search-guard-kibana-plugin.
- Which vendors does floragunn cover?
- floragunn publishes CVEs across 1 distinct vendors, most often floragunn, search-guard, floragunncom.
- Is floragunn actively publishing CVEs?
- floragunn is currently active, based on 4 CVEs in the last two years.
- What is the average severity of floragunn's CVEs?
- The average CVSS base score across floragunn's scored CVEs is 5.6.
- Are any of floragunn's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of floragunn's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in floragunn's CVEs?
- floragunn's CVEs most often map to these CWE weakness types: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-311 (Missing Encryption of Sensitive Data), CWE-285 (Improper Authorization), CWE-287 (Improper Authentication).
- How does floragunn rank among CNAs?
- By total CVE volume, floragunn ranks #278 of 370 CNAs, and it reports more complete CVE records than 31% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track floragunn CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.