← Back

Grafana

grafana

125 CVEs • 17 products

Products (17)

Click to collapse
Toggle
Grafana
grafana
Tempo
tempo
Loki
loki
Agent
agent
Google Sheets
google_sheets
Worldmap Panel
worldmap_panel
Oncall
oncall
Alloy
alloy
Pyroscope
pyroscope
Snowflake
snowflake

CVEs (125)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Grafana
1Piechart Panel
Nov 21, 2024
Feb 6, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote u...Show more
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard.Show less
1Grafana
1Grafana
Nov 21, 2024
Dec 20, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear...Show more
Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..Show less
3Grafana
NetappRedhat
7Active Iq Performance Analytics Services
Ceph StorageEnterprise Linux Desktop+4 more
Nov 21, 2024
Dec 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
2Grafana
Redhat
2Ceph Storage
Grafana
Nov 21, 2024
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.
2Grafana
Netapp
3Active Iq Performance Analytics Services
GrafanaStoragegrid Webscale Nas Bridge
Nov 21, 2024
Jun 11, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.