Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-11110EPSS 10% Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript … Grafana after 6.7.1 Fix from $1,6002020-07-27 HIGH 8.2 CVE-2020-13379EPSS 100% The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clie… Grafana after 7.0.1 Fix from $1,9502020-06-03 MEDIUM 6.1 CVE-2018-18623 Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. Grafana Patch available Fix from $1,6002020-06-02 MEDIUM 6.1 CVE-2018-18624 Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-1… Grafana Patch available Fix from $1,6002020-06-02 MEDIUM 6.1 CVE-2018-18625 Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-… Grafana Patch available Fix from $1,6002020-06-02 MEDIUM 6.1 CVE-2020-13430 Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. Grafana 7.0.0+ Fix from $1,6002020-05-24 MEDIUM 5.4 CVE-2020-13429 legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option. Piechart Panel 1.5.0+ Fix from $1,6002020-05-24 MEDIUM 5.5 CVE-2020-12458 An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana… Grafana after 6.7.3 Fix from $1,6002020-04-29 MEDIUM 5.5 CVE-2020-12459 In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain… Grafana after 6.3.6 Fix from $1,6002020-04-29 MEDIUM 6.1 CVE-2020-12052 Grafana version < 6.7.3 is vulnerable for annotation popup XSS. Grafana 6.7.3+ Fix from $1,6002020-04-27 MEDIUM 6.1 CVE-2020-12245 Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip. Grafana 6.7.3+ Fix from $1,6002020-04-24 HIGH 7.5 CVE-2019-15043EPSS 63% In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack ag… Grafana 5.4.5 / 6.3.4+ Fix from $1,9502019-09-03 MEDIUM 5.4 CVE-2019-13068EPSS 52% public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field). Grafana 6.2.5+ Fix from $1,6002019-06-30 MEDIUM 6.1 CVE-2015-9282 The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana… Piechart Panel after 1.3.4 Fix from $1,6002019-02-06 MEDIUM 5.4 CVE-2018-1000816 Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can resu… Grafana No fix yet Fix from $1,6002018-12-20 MEDIUM 6.5 CVE-2018-19039EPSS 7% Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions. Grafana 4.6.5 / 5.3.3+ Fix from $1,6002018-12-13 CRITICAL 9.8 CVE-2018-15727EPSS 64% Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cooki… Grafana 4.6.4 / 5.2.3+ Fix from $2,3002018-08-29 MEDIUM 6.1 CVE-2018-12099 Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links. Grafana after 5.1.3 Fix from $1,6002018-06-11