Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-41117 Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require ma… Grafana 12.2.4 / 12.3.2+ Fix from $1,6002026-02-12 HIGH 8.1 CVE-2026-21721 The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who… Grafana 11.6.9 / 12.0.8+ Fix from $1,9502026-01-27 HIGH 7.5 CVE-2026-21720 Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer tha… Grafana 11.6.9 / 12.0.8+ Fix from $1,9502026-01-27 CRITICAL 9.8 CVE-2025-41115EPSS 17% SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by i… Grafana 12.2.1+ Fix from $2,3002025-11-21 MEDIUM 6.1 CVE-2025-4123EPSS 98% A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to … Grafana 10.4.18 / 11.2.9+ Fix from $1,6002025-05-22 HIGH 8.8 CVE-2024-9264EPSS 95% The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie… Grafana Mitigation only Fix from $1,9502024-10-18 HIGH 7.8 CVE-2024-8975 Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Al… Alloy 1.3.3+ Fix from $1,9502024-09-25 HIGH 7.8 CVE-2024-8996 Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issu… Agent 0.43.2+ Fix from $1,9502024-09-25 CRITICAL 9.1 CVE-2024-5526 Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces th… Oncall 1.5.2+ Fix from $2,3002024-06-05 HIGH 8.8 CVE-2024-1442 A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user acc… Grafana 9.5.7 / 10.0.12+ Fix from $1,9502024-03-07 HIGH 8.0 CVE-2023-5123 The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that… Json Api Data Source 1.3.21+ Fix from $1,9502024-02-14 MEDIUM 5.3 CVE-2023-5122 Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a… Grafana 0.6.13+ Fix from $1,6002024-02-14 MEDIUM 5.4 CVE-2023-6152 A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "veri… Grafana after 2.5.0 Fix from $1,6002024-02-13 MEDIUM 6.1 CVE-2023-3010 Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerabil… Worldmap Panel 1.0.4+ Fix from $1,6002023-10-25 HIGH 7.2 CVE-2023-4399 Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to c… Grafana 9.4.17 / 9.5.13+ Fix from $1,9502023-10-17 HIGH 7.5 CVE-2023-4457 Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are v… Google Sheets after 1.2.2 Fix from $1,9502023-10-16 HIGH 7.2 CVE-2023-4822 Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allo… Grafana 9.4.16 / 9.5.11+ Fix from $1,9502023-10-16 CRITICAL 9.8 CVE-2023-3128 Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. … Grafana 8.5.27 / 9.2.20+ Fix from $2,3002023-06-22 MEDIUM 6.4 CVE-2023-2183 Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for us… Grafana 8.5.26 / 9.2.19+ Fix from $1,6002023-06-06 MEDIUM 5.3 CVE-2023-2801 Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using m… Grafana 9.4.12 / 9.5.3+ Fix from $1,6002023-06-06 HIGH 7.5 CVE-2023-1387 Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a J… Grafana 9.2.17 / 9.3.13+ Fix from $1,9502023-04-26 MEDIUM 5.4 CVE-2023-22462 Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team… Grafana 9.2.10 / 9.3.4+ Fix from $1,6002023-03-02 MEDIUM 5.4 CVE-2023-0507EPSS 15% Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting… Grafana 8.5.21 / 9.2.13+ Fix from $1,6002023-03-01 MEDIUM 5.4 CVE-2023-0594EPSS 9% Grafana is an open-source platform for monitoring and observability. Starting with the 7.0 branch, Grafana had a stored XSS vulnerability in the tr… Grafana 8.5.21 / 9.2.13+ Fix from $1,6002023-03-01 HIGH 8.8 CVE-2022-23498 Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including … Grafana 9.2.10 / 9.3.4+ Fix from $1,9502023-02-03 MEDIUM 5.4 CVE-2022-23552 Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Gr… Grafana 8.5.16 / 9.2.10+ Fix from $1,6002023-01-27 HIGH 8.8 CVE-2022-44643 A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an acce… Enterprise Metrics 1.7.1 / 2.3.1+ Fix from $1,9502022-12-20 MEDIUM 5.3 CVE-2022-39307 Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the … Grafana 8.5.15 / 9.2.4+ Fix from $1,6002022-11-09 HIGH 8.1 CVE-2022-39306 Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper In… Grafana 8.5.15 / 9.2.4+ Fix from $1,9502022-11-09 HIGH 8.1 CVE-2022-39328 Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the… Grafana 9.2.4+ Fix from $1,9502022-11-08