Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 574

Количество 574

nvd логотип

CVE-2020-12052

больше 6 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-12052

больше 6 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-19499

почти 6 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2019-19499

почти 6 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-19499

почти 6 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-19499

почти 6 лет назад

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-15635

почти 7 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-15635

почти 7 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2019-15635

почти 7 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-15635

почти 7 лет назад

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2019-15043

почти 7 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-15043

почти 7 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 4.3
EPSS: Средний
nvd логотип

CVE-2019-15043

почти 7 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-15043

почти 7 лет назад

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow u ...

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2019-13068

около 7 лет назад

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
EPSS: Средний
nvd логотип

CVE-2019-13068

около 7 лет назад

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
EPSS: Средний
debian логотип

CVE-2019-13068

около 7 лет назад

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows ...

CVSS3: 5.4
EPSS: Средний
ubuntu логотип

CVE-2018-18625

около 6 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2018-18625

около 6 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-18625

около 6 лет назад

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-12052

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
4%
Низкий
почти 6 лет назад
redhat логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
4%
Низкий
почти 6 лет назад
nvd логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

CVSS3: 6.5
4%
Низкий
почти 6 лет назад
debian логотип
CVE-2019-19499

Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could ...

CVSS3: 6.5
4%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
2%
Низкий
почти 7 лет назад
redhat логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a data source's settings menu. When watching the transaction with Burp Proxy, the password for the data source is revealed and sent to the server. From a browser, a prompt to save the credentials is generated, and the password can be revealed by simply checking the "Show password" box.

CVSS3: 4.9
2%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-15635

An issue was discovered in Grafana 5.4.0. Passwords for data sources u ...

CVSS3: 4.9
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
63%
Средний
почти 7 лет назад
redhat логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 4.3
63%
Средний
почти 7 лет назад
nvd логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.

CVSS3: 7.5
63%
Средний
почти 7 лет назад
debian логотип
CVE-2019-15043

In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow u ...

CVSS3: 7.5
63%
Средний
почти 7 лет назад
ubuntu логотип
CVE-2019-13068

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
52%
Средний
около 7 лет назад
nvd логотип
CVE-2019-13068

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

CVSS3: 5.4
52%
Средний
около 7 лет назад
debian логотип
CVE-2019-13068

public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows ...

CVSS3: 5.4
52%
Средний
около 7 лет назад
ubuntu логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

CVSS3: 6.1
1%
Низкий
около 6 лет назад

Уязвимостей на страницу