Vulnerabilidades en grafana
122 resultadosAnálisis Vexday
Grafana apresenta 30 vulnerabilidades catalogadas, das quais 2 estão sob ataque ativo e 3 são críticas, configurando risco material para ambientes em produção. A fraqueza dominante é exposição de informações (CWE-200), típica de produtos web, embora nenhuma vulnerabilidade tenha sido publicada nos últimos 90 dias, sugerindo que o risco atual é estável e não inclui ameaças zero-day recentes.
CVE-2024-10452LOWOrganization admins can delete pending invites created in an organization they are not part of.EPSS 0.5%CVE-2025-1088LOWVery long unicode dashboard title or panel name can hang the frontendEPSS 0.5%CVE-2026-21729HIGHLoki detected_fields query limits results in unbounded memory allocationEPSS 0.5%CVE-2025-3580MEDIUMAn access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server adminiEPSS 0.5%CVE-2025-3454MEDIUMThis vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the UREPSS 0.5%CVE-2023-3010HIGHGrafana is an open-source platform for monitoring and observability.
The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vEPSS 0.4%CVE-2026-42129HIGHPath traversal in the Loki data source pluginEPSS 0.4%CVE-2026-33375MEDIUMGrafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoSEPSS 0.4%CVE-2026-42127HIGHPre-authentication denial of service in the public dashboard query endpointEPSS 0.4%CVE-2026-27878MEDIUMTempo TraceQL query with exemplar hint could result in unbounded memory usageEPSS 0.4%CVE-2024-11741MEDIUMGrafana is an open-source platform for monitoring and observability.
The Grafana Alerting VictorOps integration was not properly protected EPSS 0.4%CVE-2026-21726MEDIUMLoki Path Traversal - CVE-2021-36156 BypassEPSS 0.4%CVE-2025-41118CRITICALSensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protectionEPSS 0.4%CVE-2024-5526HIGHGrafana OnCall is an easy-to-use on-call management tool that will help reduce toil in on-call management through simpler workflows and inteEPSS 0.4%CVE-2026-19475MEDIUMSQL Data Source Plugin: OOM DoS via $__timeGroup macroEPSS 0.4%CVE-2026-8609MEDIUMPre-authentication denial of service via the OAuth login routeEPSS 0.4%CVE-2026-76154HIGHCVE-2026-76154 CVE RecordEPSS 0.4%CVE-2023-4457MEDIUMGrafana is an open-source platform for monitoring and observability.
The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.EPSS 0.4%CVE-2026-33382HIGHDenial of service via unbounded request body sizeEPSS 0.4%CVE-2026-28375MEDIUMGrafana Testdata datasource can issue unbounded memory allocationsEPSS 0.4%