Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 16% | — | GrafanaAI | 23/4/2025 | 17/6/2026 | The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript. | |
| Aplazada | Media (4.3) | 0.41% | — | GrafanaAI | 31/1/2025 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15 | |
| Aplazada | Media (5.1) | 0.21% | — | Grafana Labs GrafanaAIGrafana Labs Grafana Cloud Migration AssistantAI | 13/11/2024 | 17/6/2026 | A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who utilize the Organizations feature to isolate… | |
| Analizada | Baja (2.7) | 0.49% | — | Grafana | 29/10/2024 | 17/6/2026 | Organization admins can delete pending invites created in an organization they are not part of. | |
| Modificada | Crítica (9.4) | 95% | 💥 Exploit | Grafana | 18/10/2024 | 17/6/2026 | The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is… | |
| Aplazada | Media (5.1) | 0.58% | 💥 PoC | GrafanaAI | 26/9/2024 | 17/6/2026 | In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules. | |
| Analizada | Alta (7.8) | 0.26% | — | Grafana Agent | 25/9/2024 | 17/6/2026 | Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2 | |
| Analizada | Alta (7.8) | 0.30% | — | Grafana Alloy | 25/9/2024 | 17/6/2026 | Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1. | |
| Aplazada | Crítica (9.1) | 0.52% | — | Grafana Plugin SDKAI | 19/9/2024 | 17/6/2026 | The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for fetching of private dependencies), the… | |
| Aplazada | Media (5.4) | 0.30% | — | GrafanaAI | 20/8/2024 | 17/6/2026 | Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted… | |
| Modificada | Crítica (9.1) | 0.40% | — | Grafana Oncall | 5/6/2024 | 17/6/2026 | Grafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and interfaces that are tailored specifically for engineers. Grafana OnCall, from version 1.1.37 before 1.5.2 are vulnerable to a Server Side Request Forgery (SSRF) vulnerability in the… | |
| Aplazada | Media (6.5) | 0.65% | — | Grafana Labs GrafanaAI | 26/3/2024 | 17/6/2026 | It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/<key> using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot… | |
| Analizada | Alta (8.8) | 0.80% | — | Grafana | 7/3/2024 | 17/6/2026 | A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization. | |
| Analizada | Alta (8) | 0.77% | — | Grafana Json API Data Source | 14/2/2024 | 17/6/2026 | The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an administrator. Due to inadequate sanitization of… | |
| Modificada | Media (5.3) | 0.51% | — | Grafana | 14/2/2024 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured to send requests to a bare host with no… | |
| Modificada | Media (5.4) | 1.4% | — | Grafana | 13/2/2024 | 17/6/2026 | A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up. | |
| Modificada | Media (6.1) | 0.45% | — | Grafana Worldmap Panel | 25/10/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability. | |
| Modificada | Alta (7.2) | 1.1% | — | Grafana | 17/10/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance doesn’t call specific hosts. However, the restriction can be bypassed used punycode encoding of the characters in the request… | |
| Modificada | Alta (7.5) | 0.39% | — | Grafana Google Sheets | 16/10/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially expose the Google Sheet API-key that is… | |
| Modificada | Alta (7.2) | 1.1% | — | Grafana | 16/10/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The vulnerability impacts Grafana instances with several organizations, and allows a user with Organization Admin permissions in one organization to change the permissions associated with Organization Viewer, Organization Editor and Organization… | |
| Modificada | Crítica (9.8) | 4.0% | 💥 PoC | Grafana | 22/6/2023 | 17/6/2026 | Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app. | |
| Modificada | Media (5.3) | 0.74% | — | Grafana | 6/6/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Using public dashboards users can query multiple distinct data sources using mixed queries. However such query has a possibility of crashing a Grafana instance. The only feature that uses mixed queries at the moment is public dashboards, but it's… | |
| Modificada | Media (6.4) | 1.0% | — | Grafana | 6/6/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API does not check access to this function. This… | |
| Modificada | Crítica (9.8) | 4.0% | — | Tdengine Grafana | 6/6/2023 | 17/6/2026 | The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the github action context due to the insecure usage of `${{ github.event.pull_request.title }}` in a bash command within the GitHub workflow.… | |
| Modificada | Alta (7.5) | 1.5% | — | Grafana | 26/4/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "url_login" configuration option (disabled by default), a JWT might be sent… |