Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 574

Количество 574

redhat логотип

CVE-2026-33382

20 дней назад

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-33382

20 дней назад

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-33381

3 месяца назад

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-33381

3 месяца назад

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-33381

3 месяца назад

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-33381

3 месяца назад

When a user's access to mint tokens for a service account is revoked, ...

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2026-33380

3 месяца назад

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2026-33380

3 месяца назад

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2026-33380

3 месяца назад

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 6.3
EPSS: Низкий
debian логотип

CVE-2026-33380

3 месяца назад

A vulnerability in SQL Expressions allows an authenticated attacker to ...

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2026-33378

3 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-33378

3 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-33378

3 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading th ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-33377

3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-33377

3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-33377

3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-33377

3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2026-33376

3 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-33376

3 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-33376

3 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 5.3
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

CVSS3: 7.5
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2026-33381

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

CVSS3: 5.9
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-33381

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

CVSS3: 5.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33381

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this.

CVSS3: 5.9
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-33381

When a user's access to mint tokens for a service account is revoked, ...

CVSS3: 5.9
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-33380

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 6.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-33380

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 6.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33380

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

CVSS3: 6.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-33380

A vulnerability in SQL Expressions allows an authenticated attacker to ...

CVSS3: 6.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-33378

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33378

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-33378

Using the $__timeGroup macro, one can achieve an OOM by overloading th ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin ...

CVSS3: 7.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
3 месяца назад

Уязвимостей на страницу