Grafana Latest High & Critical Vulnerabilities
Latest High & Critical vulnerabilities published by grafana
Vulnerability Published:
๐๏ธ Published
- Anytime
Sort By:
๐๏ธ Published Date
- Descending
Grafana SQL Expressions Vulnerability: Command Injection and Local File Inclusion Risks
CVE-2024-9264GrafanaGrafana๐ฅ๐๐พ๐กEPSS 92%๐ฐ9.4CRITICALPrivilege Escalation Vulnerability in Grafana Alloy
CVE-2024-8975GrafanaAlloy7.8HIGHPrivilege Escalation Vulnerability in Grafana Agent Flow Mode for Windows
CVE-2024-8996GrafanaAgent Flow7.8HIGHServer Side Request Forgery in Grafana OnCall by Grafana Labs
CVE-2024-5526GrafanaOncall9.1CRITICALGranting Unrestricted Access to Data Sources Through UID
CVE-2024-1442GrafanaGrafana8.8HIGHGrafana JSON datasource plugin vulnerability
CVE-2023-5123GrafanaGrafana-json-datasource8HIGHRequest Filtering Bypass in Grafana Enterprise by Grafana Labs
CVE-2023-4399GrafanaGrafana Enterprise7.2HIGHPrivilege Escalation in Grafana by Organization Admins
CVE-2023-4822GrafanaGrafana Enterprise7.2HIGHAccount Takeover Vulnerability in Grafana for Azure AD Accounts
CVE-2023-3128GrafanaGrafana9.8CRITICALAuthentication Bypass in Grafana Monitoring Platform
CVE-2023-1387GrafanaGrafana7.5HIGHStored XSS Vulnerability in Grafana's GeoMap Plugin
CVE-2023-0507GrafanaGrafanaEPSS 66%7.3HIGHStored XSS Vulnerability in Grafana Monitoring Platform
CVE-2023-0594GrafanaGrafanaEPSS 34%7.3HIGHWhen query caching is enabled in Grafana users can query another users session
CVE-2022-23498GrafanaGrafana7.1HIGHGrafana stored XSS in FileUploader component
CVE-2022-23552GrafanaGrafana7.3HIGHAccess policy with access to all tenants and using label selectors has more access
CVE-2022-44643GrafanaEnterprise Metrics๐พ8.8HIGHGrafana's default installation of `synthetic-monitoring-agent` exposes sensitive information
CVE-2022-46156GrafanaSynthetic-monitoring-a...7.2HIGHGrafana vulnerable to race condition allowing privilege escalation
CVE-2022-39328GrafanaGrafana9.8CRITICALGrafana folders admin only permission privilege escalation
CVE-2022-36062GrafanaGrafana7.6HIGHGrafana Image Renderer leaking files
CVE-2022-31176GrafanaGrafana-image-renderer8.3HIGHGrafana account takeover via OAuth vulnerability
CVE-2022-31107GrafanaGrafana7.1HIGHStored XSS in Grafana's Unified Alerting
CVE-2022-31097GrafanaGrafanaEPSS 49%7.3HIGHUnauthenticated Access in Grafana by Grafana Labs
CVE-2022-32276GrafanaGrafanaEPSS 11%7.5HIGHFile Reading Vulnerability in Grafana by Grafana Labs
CVE-2022-32275GrafanaGrafanaEPSS 60%7.5HIGHAuthentication Bypass in Grafana Enterprise Logs by Grafana Labs
CVE-2022-28660GrafanaGrafana9.8CRITICALFGAC API Key privilege escalation in Grafana
CVE-2022-24812GrafanaGrafana8HIGH