Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2025-41117
Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require ma…
Grafana
12.2.4 / 12.3.2+
HIGH 8.1
CVE-2026-21721
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who…
Grafana
11.6.9 / 12.0.8+
HIGH 7.5
CVE-2026-21720
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer tha…
Grafana
11.6.9 / 12.0.8+
CRITICAL 9.8
CVE-2025-41115EPSS 17%
SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i…
Grafana
12.2.1+
MEDIUM 6.1
CVE-2025-4123EPSS 98%
A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to …
Grafana
10.4.18 / 11.2.9+
HIGH 8.8
CVE-2024-9264EPSS 95%
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie…
Grafana
Mitigation only
HIGH 7.8
CVE-2024-8975
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM
This issue affects Al…
Alloy
1.3.3+
HIGH 7.8
CVE-2024-8996
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM
This issu…
Agent
0.43.2+
CRITICAL 9.1
CVE-2024-5526
Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces th…
Oncall
1.5.2+
HIGH 8.8
CVE-2024-1442
A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *.
Doing this will grant the user acc…
Grafana
9.5.7 / 10.0.12+
HIGH 8.0
CVE-2023-5123
The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that…
Json Api Data Source
1.3.21+
MEDIUM 5.3
CVE-2023-5122
Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a…
Grafana
0.6.13+
MEDIUM 5.4
CVE-2023-6152
A user changing their email after signing up and verifying it can change it without verification in profile settings.
The configuration option "veri…
Grafana
after 2.5.0
MEDIUM 6.1
CVE-2023-3010
Grafana is an open-source platform for monitoring and observability.
The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerabil…
Worldmap Panel
1.0.4+
HIGH 7.2
CVE-2023-4399
Grafana is an open-source platform for monitoring and observability.
In Grafana Enterprise, Request security is a deny list that allows admins to c…
Grafana
9.4.17 / 9.5.13+
HIGH 7.5
CVE-2023-4457
Grafana is an open-source platform for monitoring and observability.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are v…
Google Sheets
after 1.2.2
HIGH 7.2
CVE-2023-4822
Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allo…
Grafana
9.4.16 / 9.5.11+
CRITICAL 9.8
CVE-2023-3128
Grafana is validating Azure AD accounts based on the email claim.
On Azure AD, the profile email field is not unique and can be easily modified.
…
Grafana
8.5.27 / 9.2.20+
MEDIUM 6.4
CVE-2023-2183
Grafana is an open-source platform for monitoring and observability.
The option to send a test alert is not available from the user panel UI for us…
Grafana
8.5.26 / 9.2.19+
MEDIUM 5.3
CVE-2023-2801
Grafana is an open-source platform for monitoring and observability.
Using public dashboards users can query multiple distinct data sources using m…
Grafana
9.4.12 / 9.5.3+
HIGH 7.5
CVE-2023-1387
Grafana is an open-source platform for monitoring and observability.
Starting with the 9.1 branch, Grafana introduced the ability to search for a J…
Grafana
9.2.17 / 9.3.13+
MEDIUM 5.4
CVE-2023-22462
Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team…
Grafana
9.2.10 / 9.3.4+
MEDIUM 5.4
CVE-2023-0507EPSS 15%
Grafana is an open-source platform for monitoring and observability.
Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting…
Grafana
8.5.21 / 9.2.13+
MEDIUM 5.4
CVE-2023-0594EPSS 9%
Grafana is an open-source platform for monitoring and observability.
Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the tr…
Grafana
8.5.21 / 9.2.13+
HIGH 8.8
CVE-2022-23498
Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including …
Grafana
9.2.10 / 9.3.4+
MEDIUM 5.4
CVE-2022-23552
Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Gr…
Grafana
8.5.16 / 9.2.10+
HIGH 8.8
CVE-2022-44643
A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an acce…
Enterprise Metrics
1.7.1 / 2.3.1+
MEDIUM 5.3
CVE-2022-39307
Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the …
Grafana
8.5.15 / 9.2.4+
HIGH 8.1
CVE-2022-39306
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper In…
Grafana
8.5.15 / 9.2.4+
HIGH 8.1
CVE-2022-39328
Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the…
Grafana
9.2.4+