Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 602

Количество 602

github логотип

GHSA-4724-7jwc-3fpw

больше 2 лет назад

Grafana Spoofing originalUrl of snapshots

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-46x4-c48q-4248

больше 4 лет назад

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

EPSS: Низкий
github логотип

GHSA-4368-7mjc-5763

6 месяцев назад

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3w66-95m3-8jxg

3 месяца назад

Grafana: Pre-authentication denial of service in the public dashboard query handler

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3r2p-7499-27q3

4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-3q27-7qjq-p9c5

6 месяцев назад

Grafana public dashboards disclose all direct mode datasources

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3p62-42x7-gxg5

больше 2 лет назад

Grafana User enumeration via forget password

CVSS3: 6.7
EPSS: Низкий
github логотип

GHSA-3j9m-hcv9-rpj8

почти 5 лет назад

XSS vulnerability allowing arbitrary JavaScript execution

CVSS3: 6.9
EPSS: Высокий
github логотип

GHSA-3hv4-r2fm-h27f

больше 2 лет назад

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3f33-44xm-29m7

7 месяцев назад

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-2x6g-h2hg-rq84

больше 2 лет назад

Grafana Email addresses and usernames can not be trusted

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-29p4-5443-x453

4 месяца назад

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-54184

около 1 месяца назад

ELSA-2026-54184: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10226

5 месяцев назад

ELSA-2026-10226: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-10223

5 месяцев назад

ELSA-2026-10223: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7894

больше 1 года назад

ELSA-2025-7894: grafana security update (IMPORTANT)

EPSS: Критический
oracle-oval логотип

ELSA-2025-7893

больше 1 года назад

ELSA-2025-7893: grafana security update (IMPORTANT)

EPSS: Критический
oracle-oval логотип

ELSA-2025-7892

около 1 года назад

ELSA-2025-7892: grafana security update (IMPORTANT)

EPSS: Критический
oracle-oval логотип

ELSA-2023-6972

почти 3 года назад

ELSA-2023-6972: grafana security and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-4030

около 3 лет назад

ELSA-2023-4030: grafana security update (CRITICAL)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4724-7jwc-3fpw

Grafana Spoofing originalUrl of snapshots

CVSS3: 6.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-46x4-c48q-4248

Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-4368-7mjc-5763

A resample query can be used to trigger out-of-memory crashes in Grafana.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3w66-95m3-8jxg

Grafana: Pre-authentication denial of service in the public dashboard query handler

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-3r2p-7499-27q3

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
0%
Низкий
4 месяца назад
github логотип
GHSA-3q27-7qjq-p9c5

Grafana public dashboards disclose all direct mode datasources

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-3p62-42x7-gxg5

Grafana User enumeration via forget password

CVSS3: 6.7
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3j9m-hcv9-rpj8

XSS vulnerability allowing arbitrary JavaScript execution

CVSS3: 6.9
85%
Высокий
почти 5 лет назад
github логотип
GHSA-3hv4-r2fm-h27f

Email Validation Bypass And Preventing Sign Up From Email's Owner

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-3f33-44xm-29m7

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

CVSS3: 5.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-2x6g-h2hg-rq84

Grafana Email addresses and usernames can not be trusted

CVSS3: 6.4
1%
Низкий
больше 2 лет назад
github логотип
GHSA-29p4-5443-x453

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
0%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-54184

ELSA-2026-54184: grafana security update (IMPORTANT)

0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-10226

ELSA-2026-10226: grafana security update (IMPORTANT)

0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-10223

ELSA-2026-10223: grafana security update (IMPORTANT)

0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-7894

ELSA-2025-7894: grafana security update (IMPORTANT)

97%
Критический
больше 1 года назад
oracle-oval логотип
ELSA-2025-7893

ELSA-2025-7893: grafana security update (IMPORTANT)

97%
Критический
больше 1 года назад
oracle-oval логотип
ELSA-2025-7892

ELSA-2025-7892: grafana security update (IMPORTANT)

97%
Критический
около 1 года назад
oracle-oval логотип
ELSA-2023-6972

ELSA-2023-6972: grafana security and enhancement update (MODERATE)

4%
Низкий
почти 3 года назад
oracle-oval логотип
ELSA-2023-4030

ELSA-2023-4030: grafana security update (CRITICAL)

4%
Низкий
около 3 лет назад

Уязвимостей на страницу