Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-39201 Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Gr… Grafana 8.5.14 / 9.1.8+ Fix from $1,9502022-10-13 HIGH 7.5 CVE-2022-31130 Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authe… Grafana 8.5.14 / 9.1.8+ Fix from $1,9502022-10-13 HIGH 7.8 CVE-2022-31123 Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin … Grafana 8.5.14 / 9.1.8+ Fix from $1,9502022-10-13 MEDIUM 6.6 CVE-2022-35957 Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to… Grafana 8.5.13 / 9.0.9+ Fix from $1,6002022-09-20 HIGH 8.1 CVE-2022-31176 Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). … Grafana Image Renderer 3.6.1+ Fix from $1,9502022-09-02 HIGH 7.5 CVE-2022-31107 Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a mal… Grafana 8.3.10 / 8.4.10+ Fix from $1,9502022-07-15 HIGH 8.7 CVE-2022-31097EPSS 69% Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are… Grafana 8.3.10 / 8.4.10+ Fix from $1,9502022-07-15 HIGH 7.5 CVE-2022-32276 Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vu… Grafana No fix yet Fix from $1,9502022-06-17 HIGH 7.5 CVE-2022-32275EPSS 9% Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd … Grafana No fix yet Fix from $1,9502022-06-06 HIGH 8.5 CVE-2022-29170 Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to config… Grafana 7.5.16 / 8.5.3+ Fix from $1,9502022-05-20 CRITICAL 9.8 CVE-2022-28660 The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version… Grafana 1.2.1+ Fix from $2,3002022-05-20 HIGH 8.8 CVE-2022-24812 Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to… Grafana 8.4.6+ Fix from $1,9502022-04-12 CRITICAL 9.8 CVE-2022-26148EPSS 53% An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source co… Grafana after 7.3.4 Fix from $2,3002022-03-21 HIGH 8.8 CVE-2022-21703 Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic… Grafana 3.0 / 7.5.15+ Fix from $1,9502022-02-08 MEDIUM 5.4 CVE-2022-21702 Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datas… Grafana 3.0 / 7.5.15+ Fix from $1,6002022-02-08 HIGH 7.5 CVE-2021-41090 Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.… Agent 0.20.1 / 0.21.2+ Fix from $1,9502021-12-08 HIGH 7.5 CVE-2021-43798 KEVEPSS 89% Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vul… Grafana 8.0.7 / 8.1.8+ Fix from $1,9502021-12-07 HIGH 7.2 CVE-2021-41244 Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enable… Grafana 8.2.4+ Fix from $1,9502021-11-15 MEDIUM 6.1 CVE-2021-41174EPSS 85% Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL … Grafana 8.2.3+ Fix from $1,6002021-11-03 HIGH 7.3 CVE-2021-39226 KEVEPSS 100% Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit… Grafana 7.5.11 / 8.1.6+ Fix from $1,9502021-10-05 MEDIUM 5.3 CVE-2021-36156 An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted… Loki after 2.2.1 Fix from $1,6002021-08-03 MEDIUM 5.5 CVE-2021-31231 The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.… Enterprise Metrics 1.2.1+ Fix from $1,6002021-04-30 HIGH 7.5 CVE-2021-28148 One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without … Grafana 6.7.6 / 7.3.10+ Fix from $1,9502021-03-22 MEDIUM 6.5 CVE-2021-28147 The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Gr… Grafana 6.7.6 / 7.3.10+ Fix from $1,6002021-03-22 HIGH 7.1 CVE-2021-27962 Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data sour… Grafana 7.3.10 / 7.4.5+ Fix from $1,9502021-03-22 MEDIUM 6.5 CVE-2021-28146 The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authent… Grafana 7.4.5+ Fix from $1,6002021-03-22 HIGH 7.5 CVE-2021-27358EPSS 83% The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API cal… Grafana after 7.4.1 Fix from $1,9502021-03-18 CRITICAL 9.8 CVE-2020-27846 A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th… Grafana 0.4.3 / 6.7.5+ Fix from $2,3002020-12-21 MEDIUM 6.1 CVE-2020-24303 Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. Grafana after 7.0.5 Fix from $1,6002020-10-28 MEDIUM 6.5 CVE-2019-19499 Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the da… Grafana after 6.4.3 Fix from $1,6002020-08-28