Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 602

Количество 602

rocky логотип

RLSA-2026:54184

8 дней назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2026:10226

5 месяцев назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2026:10223

5 месяцев назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2025:7894

около 1 года назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7893

12 месяцев назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2025:7892

12 месяцев назад

Important: grafana security update

EPSS: Критический
rocky логотип

RLSA-2023:4030

около 3 лет назад

Critical: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2022:1781

больше 4 лет назад

Low: grafana security, bug fix, and enhancement update

EPSS: Средний
rocky логотип

RLSA-2021:3771

почти 5 лет назад

Important: grafana security update

EPSS: Критический
github логотип

GHSA-xw5p-hw8j-xg4q

больше 3 лет назад

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xfc5-hp99-89qr

больше 4 лет назад

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

EPSS: Низкий
github логотип

GHSA-xcrv-g5fh-9wx2

3 месяца назад

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x94r-qqxh-wpj5

3 месяца назад

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-x744-mm8v-vpgr

больше 2 лет назад

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-x5fh-fvvr-892f

больше 4 лет назад

Grafana XSS Vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x2w4-c67p-g44j

больше 3 лет назад

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wfhv-mj62-f5xh

4 месяца назад

Grafana: Users can generate Service Account tokens after permissions removal

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-w62r-7c53-fmc5

10 месяцев назад

Grafana Incorrect Privilege Assignment vulnerability

CVSS3: 10
EPSS: Средний
github логотип

GHSA-w36g-f98m-wm99

7 месяцев назад

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-vqc4-mpj8-jxch

больше 2 лет назад

Grafana Race condition allowing privilege escalation

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:54184

Important: grafana security update

0%
Низкий
8 дней назад
rocky логотип
RLSA-2026:10226

Important: grafana security update

0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2026:10223

Important: grafana security update

0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2025:7894

Important: grafana security update

97%
Критический
около 1 года назад
rocky логотип
RLSA-2025:7893

Important: grafana security update

97%
Критический
12 месяцев назад
rocky логотип
RLSA-2025:7892

Important: grafana security update

97%
Критический
12 месяцев назад
rocky логотип
RLSA-2023:4030

Critical: grafana security update

4%
Низкий
около 3 лет назад
rocky логотип
RLSA-2022:1781

Low: grafana security, bug fix, and enhancement update

57%
Средний
больше 4 лет назад
rocky логотип
RLSA-2021:3771

Important: grafana security update

100%
Критический
почти 5 лет назад
github логотип
GHSA-xw5p-hw8j-xg4q

Grafana vulnerable to Cross-site Scripting

CVSS3: 5.4
9%
Низкий
больше 3 лет назад
github логотип
GHSA-xfc5-hp99-89qr

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-xcrv-g5fh-9wx2

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-x94r-qqxh-wpj5

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-x744-mm8v-vpgr

Grafana Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

CVSS3: 6.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-x5fh-fvvr-892f

Grafana XSS Vulnerability

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-x2w4-c67p-g44j

Grafana Missing Synchronization vulnerability

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wfhv-mj62-f5xh

Grafana: Users can generate Service Account tokens after permissions removal

CVSS3: 5.9
0%
Низкий
4 месяца назад
github логотип
GHSA-w62r-7c53-fmc5

Grafana Incorrect Privilege Assignment vulnerability

CVSS3: 10
19%
Средний
10 месяцев назад
github логотип
GHSA-w36g-f98m-wm99

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The new datasource must not have the attacker as an admin. - The new datasource must have the same UID as the prior datasource. These are randomised by default. - The datasource can now be re-deleted by the attacker. - Once 30 seconds are up, the attack is spent and cannot be repeated. - No datasource with any other UID can be attacked.

CVSS3: 2.6
0%
Низкий
7 месяцев назад
github логотип
GHSA-vqc4-mpj8-jxch

Grafana Race condition allowing privilege escalation

CVSS3: 9.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу