Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-39201
Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Gr…
Grafana
8.5.14 / 9.1.8+
HIGH 7.5
CVE-2022-31130
Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authe…
Grafana
8.5.14 / 9.1.8+
HIGH 7.8
CVE-2022-31123
Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin …
Grafana
8.5.14 / 9.1.8+
MEDIUM 6.6
CVE-2022-35957
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to…
Grafana
8.5.13 / 9.0.9+
HIGH 8.1
CVE-2022-31176
Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). …
Grafana Image Renderer
3.6.1+
HIGH 7.5
CVE-2022-31107
Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a mal…
Grafana
8.3.10 / 8.4.10+
HIGH 8.7
CVE-2022-31097EPSS 69%
Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are…
Grafana
8.3.10 / 8.4.10+
HIGH 7.5
CVE-2022-32276
Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vu…
Grafana
No fix yet
HIGH 7.5
CVE-2022-32275EPSS 9%
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd …
Grafana
No fix yet
HIGH 8.5
CVE-2022-29170
Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to config…
Grafana
7.5.16 / 8.5.3+
CRITICAL 9.8
CVE-2022-28660
The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Version…
Grafana
1.2.1+
HIGH 8.8
CVE-2022-24812
Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to…
Grafana
8.4.6+
CRITICAL 9.8
CVE-2022-26148EPSS 53%
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source co…
Grafana
after 7.3.4
HIGH 8.8
CVE-2022-21703
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability whic…
Grafana
3.0 / 7.5.15+
MEDIUM 5.4
CVE-2022-21702
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datas…
Grafana
3.0 / 7.5.15+
HIGH 7.5
CVE-2021-41090
Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.…
Agent
0.20.1 / 0.21.2+
HIGH 7.5
CVE-2021-43798 KEVEPSS 89%
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vul…
Grafana
8.0.7 / 8.1.8+
HIGH 7.2
CVE-2021-41244
Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enable…
Grafana
8.2.4+
MEDIUM 6.1
CVE-2021-41174EPSS 85%
Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL …
Grafana
8.2.3+
HIGH 7.3
CVE-2021-39226 KEVEPSS 100%
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot wit…
Grafana
7.5.11 / 8.1.6+
MEDIUM 5.3
CVE-2021-36156
An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted…
Loki
after 2.2.1
MEDIUM 5.5
CVE-2021-31231
The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.…
Enterprise Metrics
1.2.1+
HIGH 7.5
CVE-2021-28148
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without …
Grafana
6.7.6 / 7.3.10+
MEDIUM 6.5
CVE-2021-28147
The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Gr…
Grafana
6.7.6 / 7.3.10+
HIGH 7.1
CVE-2021-27962
Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data sour…
Grafana
7.3.10 / 7.4.5+
MEDIUM 6.5
CVE-2021-28146
The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authent…
Grafana
7.4.5+
HIGH 7.5
CVE-2021-27358EPSS 83%
The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API cal…
Grafana
after 7.4.1
CRITICAL 9.8
CVE-2020-27846
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from th…
Grafana
0.4.3 / 6.7.5+
MEDIUM 6.1
CVE-2020-24303
Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.
Grafana
after 7.0.5
MEDIUM 6.5
CVE-2019-19499
Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the da…
Grafana
after 6.4.3