Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 574

Количество 574

github логотип

GHSA-4368-7mjc-5763

4 месяца назад

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w66-95m3-8jxg

около 1 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3r2p-7499-27q3

3 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3q27-7qjq-p9c5

4 месяца назад

Grafana public dashboards disclose all direct mode datasources

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p62-42x7-gxg5

около 2 лет назад

Grafana User enumeration via forget password

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3j9m-hcv9-rpj8

больше 4 лет назад

XSS vulnerability allowing arbitrary JavaScript execution

CVSS3: 6.9
EPSS: Высокий
github логотип

GHSA-3hv4-r2fm-h27f

больше 2 лет назад

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f33-44xm-29m7

6 месяцев назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2x6g-h2hg-rq84

около 2 лет назад

Grafana Email addresses and usernames can not be trusted

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-29p4-5443-x453

3 месяца назад

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2026-9029

около 1 месяца назад

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-9029

около 1 месяца назад

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-9029

около 1 месяца назад

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2026-9029

около 1 месяца назад

A user with Editor permissions can place a malicious script in the att ...

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-8609

20 дней назад

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-8609

20 дней назад

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-8595

20 дней назад

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2026-8595

20 дней назад

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2026-42127

около 1 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42127

около 1 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4368-7mjc-5763

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3w66-95m3-8jxg

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-3r2p-7499-27q3

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
3 месяца назад
github логотип
GHSA-3q27-7qjq-p9c5

Grafana public dashboards disclose all direct mode datasources

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-3p62-42x7-gxg5

Grafana User enumeration via forget password

CVSS3: 6.7
1%
Низкий
около 2 лет назад
github логотип
GHSA-3j9m-hcv9-rpj8

XSS vulnerability allowing arbitrary JavaScript execution

CVSS3: 6.9
85%
Высокий
больше 4 лет назад
github логотип
GHSA-3hv4-r2fm-h27f

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3f33-44xm-29m7

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-2x6g-h2hg-rq84

Grafana Email addresses and usernames can not be trusted

CVSS3: 6.4
1%
Низкий
около 2 лет назад
github логотип
GHSA-29p4-5443-x453

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-9029

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-9029

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-9029

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-9029

A user with Editor permissions can place a malicious script in the att ...

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

CVSS3: 5.3
0%
Низкий
20 дней назад
redhat логотип
CVE-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVSS3: 5.7
0%
Низкий
20 дней назад
nvd логотип
CVE-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

CVSS3: 6.8
0%
Низкий
20 дней назад
ubuntu логотип
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу