grafana
CVE Severity Distribution (All Time)
Timeline Overview
Recent CVEs
View allOrganization admins can delete pending invites created in an organization they are not part of.
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie…
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to…
Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issu…
Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Al…
Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is grante…