Where
-Infinity
0

Grafana GrafanaThis vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by a…

Risk 26
Severity
5
First published (updated )

go/github.com/grafana/grafanaOrganization admins can delete pending invites created in an organization they are not part of.

Risk 16
Severity
2.7
First published (updated )

go/github.com/grafana/grafanaGrafana SQL Expressions allow for remote code execution

Risk 67
Severity
10
EPSS
18.48%
First published (updated )

Grafana GrafanaGrafana alerting wrong permission on datasource rule write endpoint

Risk 28
Severity
5.1
EPSS
0.04%
First published (updated )

redhat/grafanaUser with permissions to create a data source can CRUD all data sources

Risk 83
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grafana GrafanaSSRF in CSV Datasource Plugin

Risk 27
Severity
5.3
First published (updated )

Grafana GrafanaA user changing their email after signing up and verifying it can change it without verification in …

Risk 36
Severity
5.4
First published (updated )

Grafana GrafanaGrafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Reques…

Risk 66
Severity
7.2
First published (updated )

redhat/grafanaGrafana is an open-source platform for monitoring and observability. The option to send a test ale…

Risk 39
Severity
6.4
First published (updated )

redhat/grafanaRace Condition

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grafana GrafanaInfoleak

Risk 43
Severity
7.5
First published (updated )

redhat/GrafanaStored XSS in Graphite FunctionDescription tooltip

Risk 39
Severity
6.2
First published (updated )

redhat/grafanaGrafana users with email as a username can block other users from signing in

Risk 24
Severity
4.3
First published (updated )

Grafana GrafanaCVE-2022-39229: Using email as a username can block other users from signing in Currently, a user’…

Risk 19
Severity
4
First published (updated )

Grafana GrafanaData source and plugin proxy endpoints could leak the authentication cookie to some destination plugins

Risk 46
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grafana GrafanaCVE-2022-31123: Plugin signature bypass It is possible to bypass plugin signatures by exploiting a…

Risk 19
Severity
4
First published (updated )

go/github.com/grafana/grafanaGrafana data source and plugin proxy endpoints leaking authentication tokens to some destination plugins

Risk 46
Severity
7.5
First published (updated )

Grafana GrafanaGrafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. N…

Risk 43
Severity
7.5
First published (updated )

Grafana GrafanaPath Traversal

Risk 43
Severity
7.5
First published (updated )

Grafana GrafanaGrafana Enterprise datasource network restrictions bypass via HTTP redirects

Risk 55
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Grafana GrafanaThe querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require a…

Risk 86
Severity
9.8
First published (updated )

Grafana GrafanaAn issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password c…

Risk 19
Severity
4
First published (updated )

redhat Ceph StorageAn issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password c…

Risk 86
Severity
9.8
First published (updated )

Grafana GrafanaExposure of Sensitive Information in Grafana

Risk 24
Severity
4.3
First published (updated )

Grafana GrafanaCross Site Request Forgery in Grafana

Risk 81
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/grafanaCross site scripting in Grafana proxy

Risk 40
Severity
6.8
First published (updated )

redhat/grafanaOAuth Identity Token exposure in Grafana

Risk 24
Severity
4.3
First published (updated )

Grafana GrafanaGrafana directory traversal for `.cvs` files

Risk 23
Severity
4.3
First published (updated )

redhat/grafanaDirectory Traversal in Grafana

Risk 23
Severity
4.3
First published (updated )

go/github.com/grafana/grafanaCross organization admin control in Grafana

Risk 75
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203