Vulnerabilidades em grafana
122 resultadosAnálise Vexday
Grafana apresenta 30 vulnerabilidades catalogadas, das quais 2 estão sob ataque ativo e 3 são críticas, configurando risco material para ambientes em produção. A fraqueza dominante é exposição de informações (CWE-200), típica de produtos web, embora nenhuma vulnerabilidade tenha sido publicada nos últimos 90 dias, sugerindo que o risco atual é estável e não inclui ameaças zero-day recentes.
CVE-2026-27879MEDIUMQuery resampling can cause unbounded memory allocationsEPSS 0.4%CVE-2026-11769MEDIUMOperator - Namespaced User Path TraversalEPSS 0.4%CVE-2026-33380MEDIUMSQL Expressions Read File From DiskEPSS 0.4%CVE-2026-28381CRITICALLocal File Read/Write to Potential Privilege Escalation via Snowflake GET/PUTEPSS 0.4%CVE-2025-10630MEDIUMRegex DoS in Grafana Zabbix PluginEPSS 0.3%CVE-2026-21722MEDIUMPublic Dashboards time range restriction on annotations can be bypassedEPSS 0.3%CVE-2026-33381MEDIUMUsers can generate Service Account tokens after permissions removalEPSS 0.3%CVE-2026-28376MEDIUMGrafana Live push endpoint allows unbounded memory allocation leading to OOMEPSS 0.3%CVE-2026-33378MEDIUMGrafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup MacroEPSS 0.3%CVE-2026-28383MEDIUMGrafana plugin resources can lead to unbounded memory allocationEPSS 0.3%CVE-2026-21723MEDIUMCVE-2026-21723 RecordEPSS 0.3%CVE-2025-8341MEDIUMSSRF in Infinity Datasource PluginEPSS 0.3%CVE-2026-14199HIGHSession takeover via Auth Proxy cache key collisionEPSS 0.3%CVE-2026-27877MEDIUMPublic dashboards discloses all direct mode datasourcesEPSS 0.3%CVE-2024-6322MEDIUMAccess control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account EPSS 0.3%CVE-2024-8975HIGHGrafana Alloy on Windows Unquoted service pathEPSS 0.3%CVE-2026-9765HIGHCVE-2026-9765 CVE RecordEPSS 0.3%CVE-2026-10601MEDIUMPath traversal in the Tempo and Loki data source pluginsEPSS 0.3%CVE-2026-17183HIGHCVE-2026-17183 CVE RecordEPSS 0.3%CVE-2026-33376HIGHAuth Proxy IPv6 whitelist bypassEPSS 0.3%