Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 15% | — | Grafana | 1/3/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible due to map attributions weren't properly sanitized and allowed arbitrary JavaScript to be executed in the… | |
| Modificada | Alta (8.8) | 1.1% | — | Grafana | 3/2/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. When datasource query caching is enabled, Grafana caches all headers, including `grafana_session`. As a result, any user that queries a datasource where the caching is enabled can acquire another user’s session. To mitigate the vulnerability you can… | |
| Modificada | Baja (3.5) | 0.83% | — | Grafana | 27/1/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the snapshot, they will be presented with the… | |
| Modificada | Media (5.4) | 0.78% | — | Grafana | 27/1/2023 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions 8.5.16, 9.2.10, and 9.3.4, Grafana had a stored XSS vulnerability affecting the core plugin GeoMap. The stored XSS vulnerability was possible because SVG files weren't properly sanitized and allowed… | |
| Modificada | Alta (8.8) | 0.49% | — | Grafana Enterprise Metrics | 20/12/2022 | 17/6/2026 | A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector restrictions will not be applied when using… | |
| Modificada | Baja (3.3) | 0.51% | — | Grafana Synthetic Monitoring Agent | 30/11/2022 | 17/6/2026 | The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The authentication token used to communicate… | |
| Modificada | Media (5.3) | 0.75% | — | Grafana | 9/11/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset-email` URL. When the username or email does not exist, a JSON response contains a “user not found” message. This leaks information to… | |
| Modificada | Alta (8.1) | 0.76% | — | Grafana | 9/11/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an… | |
| Modificada | Alta (8.1) | 1.0% | — | Grafana | 8/11/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are… | |
| Modificada | Media (4.3) | 0.91% | — | Grafana | 13/10/2022 | 17/6/2026 | Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address are unique fields, that means no other user… | |
| Modificada | Alta (7.5) | 1.3% | — | Grafana | 13/10/2022 | 17/6/2026 | Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints under certain conditions. The destination… | |
| Modificada | Alta (7.5) | 1.1% | — | Grafana | 13/10/2022 | 17/6/2026 | Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The… | |
| Modificada | Alta (7.8) | 0.27% | — | GrafanaNetapp E-series Performance Analyzer | 13/10/2022 | 17/6/2026 | Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions… | |
| Modificada | Baja (3.8) | 0.75% | — | Grafana | 22/9/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where… | |
| Modificada | Media (6.6) | 1.6% | — | GrafanaFedoraproject Fedora | 20/9/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be… | |
| Modificada | Alta (8.1) | 1.1% | — | Grafana-image-renderer | 2/9/2022 | 17/6/2026 | Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some… | |
| Modificada | Alta (7.5) | 2.9% | — | GrafanaNetapp E-series Performance Analyzer | 15/7/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In versions 5.3 until 9.0.3, 8.5.9, 8.4.10, and 8.3.10, it is possible for a malicious user who has authorization to log into a Grafana instance via a configured OAuth IdP which provides a login name to take over the account of another user in that… | |
| Modificada | Alta (8.7) | 70% | — | GrafanaNetapp E-series Performance Analyzer | 15/7/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to… | |
| Modificada | Alta (7.5) | 3.8% | — | Grafana | 17/6/2022 | 17/6/2026 | Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability | |
| Modificada | Alta (7.5) | 9.6% | — | Grafana | 6/6/2022 | 17/6/2026 | Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd content | |
| Modificada | Alta (8.5) | 1.2% | 💥 PoC | Grafana | 20/5/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to configure Grafana in a way so that the instance doesn’t call or only calls specific hosts. The vulnerability present starting with version 7.4.0-beta1 and prior to versions… | |
| Modificada | Crítica (9.8) | 1.1% | — | Grafana | 20/5/2022 | 17/6/2026 | The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode | |
| Modificada | Alta (8.8) | 2.4% | — | Grafana | 12/4/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a client uses Grafana API Key to make requests, the permissions for that API Key are cached for 30 seconds for the given organization. Because of the way the cache ID is constructed, the consequent… | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | GrafanaRedhat Ceph StorageRedhat Storage | 21/3/2022 | 17/6/2026 | An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix. The Zabbix password can be found in the api_jsonrpc.php HTML source code. When the user logs in and allows the user to register, one can right click to view the source code and use Ctrl-F to search for password in api_jsonrpc.php to… | |
| Modificada | Media (4.3) | 1.2% | — | GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora | 8/2/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will… |