Loading HuntDB...

grafana

14 Products 54 CVEs

CVE Severity Distribution (All Time)

Critical
4
High
18
Medium
29
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-10452 LOW 1 year ago

Organization admins can delete pending invites created in an organization they are not part of.

CVE-2024-9264 UNKNOWN 1 year, 1 month ago

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficie…

CVE-2024-8118 UNKNOWN 1 year, 1 month ago

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to…

CVE-2024-8996 HIGH 1 year, 1 month ago

Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issu…

CVE-2024-8975 HIGH 1 year, 1 month ago

Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Al…

CVE-2024-6322 MEDIUM 1 year, 3 months ago

Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is grante…

CVE-2024-5526 HIGH 1 year, 5 months ago

Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces th…

CVE-2024-1313 MEDIUM 1 year, 7 months ago

It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE …

CVE-2024-1442 MEDIUM 1 year, 8 months ago

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user ac…

CVE-2023-5122 MEDIUM 1 year, 9 months ago

Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that a…