Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2020-11110EPSS 10%
Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript …
Grafana
after 6.7.1
HIGH 8.2
CVE-2020-13379EPSS 100%
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/clie…
Grafana
after 7.0.1
MEDIUM 6.1
CVE-2018-18623
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
Grafana
Patch available
MEDIUM 6.1
CVE-2018-18624
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-1…
Grafana
Patch available
MEDIUM 6.1
CVE-2018-18625
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-…
Grafana
Patch available
MEDIUM 6.1
CVE-2020-13430
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
Grafana
7.0.0+
MEDIUM 5.4
CVE-2020-13429
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
Piechart Panel
1.5.0+
MEDIUM 5.5
CVE-2020-12458
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana…
Grafana
after 6.7.3
MEDIUM 5.5
CVE-2020-12459
In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain…
Grafana
after 6.3.6
MEDIUM 6.1
CVE-2020-12052
Grafana version < 6.7.3 is vulnerable for annotation popup XSS.
Grafana
6.7.3+
MEDIUM 6.1
CVE-2020-12245
Grafana before 6.7.3 allows table-panel XSS via column.title or cellLinkTooltip.
Grafana
6.7.3+
HIGH 7.5
CVE-2019-15043EPSS 63%
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack ag…
Grafana
5.4.5 / 6.3.4+
MEDIUM 5.4
CVE-2019-13068EPSS 52%
public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).
Grafana
6.2.5+
MEDIUM 6.1
CVE-2015-9282
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana…
Piechart Panel
after 1.3.4
MEDIUM 5.4
CVE-2018-1000816
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can resu…
Grafana
No fix yet
MEDIUM 6.5
CVE-2018-19039EPSS 7%
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
Grafana
4.6.5 / 5.3.3+
CRITICAL 9.8
CVE-2018-15727EPSS 64%
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cooki…
Grafana
4.6.4 / 5.2.3+
MEDIUM 6.1
CVE-2018-12099
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
Grafana
after 5.1.3