Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26

Количество 26

oracle-oval логотип

ELSA-2026-54178

около 1 месяца назад

ELSA-2026-54178: grafana security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2026-33376

4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-33376

4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-33376

4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-33376

4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3r2p-7499-27q3

4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
fstec логотип

BDU:2026-07040

4 месяца назад

Уязвимость функции Auth Proxy платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20940-1

3 месяца назад

Security update for grafana

EPSS: Низкий
redos логотип

ROS-20260708-73-0029

2 месяца назад

Уязвимость grafana

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2026-33377

4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-33377

4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-33377

4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-33377

4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-5cv7-h7gr-wjgh

4 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2026-07034

4 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перезаписью списков контроля доступа, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.1
EPSS: Низкий
redos логотип

ROS-20260708-73-0030

2 месяца назад

Уязвимость grafana

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-54243

около 1 месяца назад

ELSA-2026-54243: grafana security update (IMPORTANT)

EPSS: Низкий
redhat логотип

CVE-2026-8609

2 месяца назад

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-8609

2 месяца назад

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-33382

2 месяца назад

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2026-54178

ELSA-2026-54178: grafana security, bug fix, and enhancement update (MODERATE)

около 1 месяца назад
ubuntu логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults ...

CVSS3: 7.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3r2p-7499-27q3

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07040

Уязвимость функции Auth Proxy платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 7.4
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20940-1

Security update for grafana

3 месяца назад
redos логотип
ROS-20260708-73-0029

Уязвимость grafana

CVSS3: 7.4
0%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin ...

CVSS3: 7.1
0%
Низкий
4 месяца назад
github логотип
GHSA-5cv7-h7gr-wjgh

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07034

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перезаписью списков контроля доступа, позволяющая нарушителю повысить свои привилегии

CVSS3: 7.1
0%
Низкий
4 месяца назад
redos логотип
ROS-20260708-73-0030

Уязвимость grafana

CVSS3: 7.1
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-54243

ELSA-2026-54243: grafana security update (IMPORTANT)

около 1 месяца назад
redhat логотип
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 5.3
0%
Низкий
2 месяца назад

Уязвимостей на страницу