Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 574

Количество 574

rocky логотип

RLSA-2026:10226

3 месяца назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2026:10223

3 месяца назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2025:7894

около 1 года назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7893

10 месяцев назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7892

10 месяцев назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2023:4030

около 3 лет назад

Critical: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2022:1781

около 4 лет назад

Low: grafana security, bug fix, and enhancement update

EPSS: Средний
rocky логотип

RLSA-2021:3771

почти 5 лет назад

Important: grafana security update

EPSS: Критический
github логотип

GHSA-xw5p-hw8j-xg4q

больше 3 лет назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xfc5-hp99-89qr

около 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: Низкий
github логотип

GHSA-xcrv-g5fh-9wx2

20 дней назад

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x94r-qqxh-wpj5

23 дня назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-x744-mm8v-vpgr

около 2 лет назад

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-x5fh-fvvr-892f

около 4 лет назад

Grafana XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x2w4-c67p-g44j

около 3 лет назад

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wfhv-mj62-f5xh

3 месяца назад

Grafana: Users can generate Service Account tokens after permissions removal

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-w62r-7c53-fmc5

8 месяцев назад

Grafana Incorrect Privilege Assignment vulnerability

CVSS3: 10
EPSS: Средний
github логотип

GHSA-w36g-f98m-wm99

5 месяцев назад

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-vqc4-mpj8-jxch

около 2 лет назад

Grafana Race condition allowing privilege escalation

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-vq62-87gp-hrvv

около 4 лет назад

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:10226

Important: grafana security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:10223

Important: grafana security update

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2025:7894

Important: grafana security update

98%
Критический
около 1 года назад
rocky логотип
RLSA-2025:7893

Important: grafana security update

98%
Критический
10 месяцев назад
rocky логотип
RLSA-2025:7892

Important: grafana security update

98%
Критический
10 месяцев назад
rocky логотип
RLSA-2023:4030

Critical: grafana security update

4%
Низкий
около 3 лет назад
rocky логотип
RLSA-2022:1781

Low: grafana security, bug fix, and enhancement update

57%
Средний
около 4 лет назад
rocky логотип
RLSA-2021:3771

Important: grafana security update

100%
Критический
почти 5 лет назад
github логотип
GHSA-xw5p-hw8j-xg4q

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
9%
Низкий
больше 3 лет назад
github логотип
GHSA-xfc5-hp99-89qr

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

1%
Низкий
около 4 лет назад
github логотип
GHSA-xcrv-g5fh-9wx2

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 7.5
0%
Низкий
20 дней назад
github логотип
GHSA-x94r-qqxh-wpj5

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
0%
Низкий
23 дня назад
github логотип
GHSA-x744-mm8v-vpgr

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-x5fh-fvvr-892f

Grafana XSS Vulnerability

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-x2w4-c67p-g44j

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-wfhv-mj62-f5xh

Grafana: Users can generate Service Account tokens after permissions removal

CVSS3: 5.9
0%
Низкий
3 месяца назад
github логотип
GHSA-w62r-7c53-fmc5

Grafana Incorrect Privilege Assignment vulnerability

CVSS3: 10
17%
Средний
8 месяцев назад
github логотип
GHSA-w36g-f98m-wm99

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
0%
Низкий
5 месяцев назад
github логотип
GHSA-vqc4-mpj8-jxch

Grafana Race condition allowing privilege escalation

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-vq62-87gp-hrvv

Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI.

CVSS3: 7.5
9%
Низкий
около 4 лет назад

Уязвимостей на страницу