Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.3% | — | GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora | 8/2/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An… | |
| Modificada | Media (5.4) | 2.3% | — | GrafanaNetapp E-series Performance AnalyzerFedoraproject Fedora | 8/2/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either… | |
| Modificada | Media (4.3) | 2.0% | — | GrafanaFedoraproject Fedora | 18/1/2022 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can… | |
| Modificada | Media (4.3) | 1.9% | — | Grafana | 10/12/2021 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and configured. The vulnerability is limited in… | |
| Modificada | Media (4.3) | 58% | — | Grafana | 10/12/2021 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files with the extension .md to authenticated… | |
| Modificada | Alta (7.5) | 0.76% | — | Grafana Agent | 8/12/2021 | 17/6/2026 | Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in plaintext over two endpoints: metrics instance configs defined in the base YAML… | |
| Analizada | Alta (7.5) | 89% | ⚠ Explotación activa💥 Exploit | Grafana | 7/12/2021 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any… | |
| Modificada | Alta (7.2) | 2.9% | — | Grafana | 15/11/2021 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access control beta feature is enabled and there is more than one organization in the Grafana instance admins are able to access users from other organizations. Grafana 8.0 introduced a mechanism which… | |
| Modificada | Media (6.1) | 85% | 💥 Exploit | Grafana | 3/11/2021 | 17/6/2026 | Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be… | |
| Analizada | Alta (7.3) | 100% | ⚠ Explotación activa💥 Exploit | GrafanaFedoraproject Fedora | 5/10/2021 | 17/6/2026 | Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to… | |
| Modificada | Media (5.3) | 1.5% | — | Grafana Loki | 3/8/2021 | 17/6/2026 | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Loki will attempt to parse a rules file at that location and include some of… | |
| Modificada | Media (5.5) | 0.28% | — | Grafana Enterprise Metrics | 30/4/2021 | 17/6/2026 | The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a webhook. The alertmanager templates can… | |
| Modificada | Alta (7.5) | 3.5% | — | Grafana | 22/3/2021 | 17/6/2026 | One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a… | |
| Modificada | Media (6.5) | 1.6% | — | Grafana | 22/3/2021 | 17/6/2026 | The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows any authenticated user to add external… | |
| Modificada | Media (6.5) | 1.4% | — | Grafana | 22/3/2021 | 17/6/2026 | The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the… | |
| Modificada | Alta (7.1) | 2.1% | — | Grafana | 22/3/2021 | 17/6/2026 | Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission check concerning a data source they should not be able to access. | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | GrafanaNetapp E-series Performance Analyzer | 18/3/2021 | 17/6/2026 | The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set. | |
| Modificada | Crítica (9.8) | 4.9% | — | GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+2 | 21/12/2020 | 17/6/2026 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | |
| Modificada | Media (6.1) | 2.0% | — | Grafana | 28/10/2020 | 17/6/2026 | Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource. | |
| Modificada | Media (6.5) | 3.6% | — | Grafana | 28/8/2020 | 17/6/2026 | Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations. | |
| Modificada | Media (5.4) | 9.6% | 💥 Exploit | GrafanaNetapp E-series Performance Analyzer | 27/7/2020 | 17/6/2026 | Grafana through 6.7.1 allows stored XSS due to insufficient input protection in the originalUrl field, which allows an attacker to inject JavaScript code that will be executed after clicking on Open Original Dashboard after visiting the snapshot. | |
| Modificada | Alta (8.2) | 100% | 💥 Exploit | GrafanaFedoraproject FedoraNetapp E-series Performance AnalyzerOpensuse Leap+1 | 3/6/2020 | 17/6/2026 | The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running… | |
| Modificada | Media (6.1) | 1.2% | — | Grafana | 2/6/2020 | 17/6/2026 | Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. | |
| Modificada | Media (6.1) | 1.4% | — | Grafana | 2/6/2020 | 17/6/2026 | Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. | |
| Modificada | Media (6.1) | 1.8% | — | Grafana | 2/6/2020 | 17/6/2026 | Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099. |