Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.26% | — | Grafana | 26/3/2026 | 17/6/2026 | A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission. | |
| Analizada | Media (5.4) | 0.26% | — | Ekacnet Grafanacubism-panel | 11/3/2026 | 17/6/2026 | The grafanacubism-panel plugin allows use of cubism.js in Grafana. In 0.1.2 and earlier, the panel's zoom-link handler passes a dashboard-editor-supplied URL directly to window.location.assign() / window.open() with no scheme validation. An attacker with dashboard Editor privileges can set the link to a javascript:… | |
| Modificada | Baja (2) | 0.17% | — | Grafana | 25/2/2026 | 17/6/2026 | A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion,… | |
| Aplazada | Alta (8.1) | 0.53% | — | Thembay FanaAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35. | |
| Modificada | Media (5.3) | 0.34% | — | Grafana | 12/2/2026 | 17/6/2026 | Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not… | |
| Modificada | Media (6.1) | 0.25% | — | Grafana | 12/2/2026 | 17/6/2026 | Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected… | |
| Modificada | Alta (8.1) | 0.73% | 💥 PoC | Grafana | 27/1/2026 | 20/7/2026 | The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation. | |
| Modificada | Alta (7.5) | 0.70% | — | Grafana | 27/1/2026 | 15/7/2026 | Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic… | |
| Aplazada | Alta (7.5) | 0.39% | — | Thembay FanaAI | 24/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35. | |
| Analizada | Crítica (9.8) | 17% | 💥 PoC | Grafana | 21/11/2025 | 17/6/2026 | SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is enabled and configured, a vulnerability in user identity handling… | |
| Aplazada | Baja (2.1) | 0.27% | — | Grafana Databricks Datasource PluginAI | 11/11/2025 | 17/6/2026 | When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it could result in the wrong user identifier being used, and information for which the viewer is not authorized being… | |
| Aplazada | Baja (2.1) | 0.27% | — | Grafana Snowflake Datasource PluginAI | 11/11/2025 | 17/6/2026 | When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it could result in the wrong user identifier being used, and information for which the viewer is not authorized being… | |
| Aplazada | Crítica (9.9) | 0.64% | — | Grafana Image RendererAI | 9/10/2025 | 17/6/2026 | Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then loaded by the Chromium… | |
| Aplazada | Media (4.3) | 0.35% | — | Grafana-zabbixAI | 19/9/2025 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring. Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which… | |
| Aplazada | Crítica (9) | 0.31% | — | Volkov Labs Business LinksAIGrafanaAI | 8/9/2025 | 17/6/2026 | The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious actor with Editor privileges can escalate their privileges to Administrator and perform arbitrary administrative actions.… | |
| Aplazada | Media (5) | 0.33% | — | Grafana InfinityAIGrafanaAI | 4/8/2025 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The Infinity datasource plugin, maintained by Grafana Labs, allows visualizing data from JSON, CSV, XML, GraphQL, and HTML endpoints. If the plugin was configured to allow only certain URLs, an attacker could bypass this restriction using a specially… | |
| Aplazada | Media (4.2) | 72% | 💥 Exploit | Grafana OSSAI | 18/7/2025 | 17/6/2026 | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL | |
| Aplazada | Alta (7.6) | 50% | — | GrafanaAI | 18/7/2025 | 17/6/2026 | An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01,… | |
| Aplazada | Media (4.3) | 1.1% | 💥 Exploit | GrafanaAI | 17/7/2025 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01,… | |
| Aplazada | Baja (2.7) | 0.47% | — | GrafanaAI | 18/6/2025 | 17/6/2026 | In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher. | |
| Aplazada | Alta (8.1) | 0.58% | — | Thembay FanaAI | 17/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.28. | |
| Aplazada | Media (5) | 0.46% | — | GrafanaAIPrometheus AlertmanagerAIPrometheusAI | 2/6/2025 | 17/6/2026 | This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources… | |
| Aplazada | Alta (8.3) | 0.56% | — | GrafanaAI | 2/6/2025 | 17/6/2026 | A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can… | |
| Aplazada | Media (5.5) | 0.46% | — | Grafana OSSAI | 23/5/2025 | 17/6/2026 | An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server… | |
| Modificada | Media (6.1) | 97% | 💥 Exploit | Grafana | 22/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous… |