Showing 24 results, page 3 of 6
| Published | CVE | Severity (CVSS) | Product | Advisory Title | Updated |
|---|---|---|---|---|---|
| 2026-03-16 | CVE-2026-28377 | High (7.5) | Tempo | S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint | — |
| 2026-02-25 | CVE-2026-21725 | Low (2.6) | Grafana | Authorization bypass in Grafana datasource deletion | — |
| 2026-02-12 | CVE-2026-21722 | Medium (5.3) | Grafana | Public Dashboards time range restriction on annotations can be bypassed | — |
| 2026-02-12 | CVE-2025-41117 | Medium (6.8) | Grafana | XSS in Grafana Explore stack trace | — |
| 2026-01-29 | CVE-2026-21727 | Low (3.3) | Grafana | Cross-Tenant Legacy Correlation Disclosure and Deletion | — |
| 2026-01-27 | CVE-2026-21721 | High (8.1) | Grafana | Cross-dashboard privilege escalation via permission management | — |
| 2026-01-27 | CVE-2026-21720 | High (7.5) | Grafana | Unauthenticated DoS in avatar cache in Grafana | — |
| 2026-01-26 | CVE-2026-21726 | Medium (5.3) | Loki | Open Redirect Loki Path Traversal - CVE-2021-36156 Bypass | — |
| 2026-01-02 | CVE-2025-41118 | Critical (9.1) | Pyroscope | Exposure of Storage Secret in Pyroscope | — |
| 2025-12-16 | CVE-2025-12141 | Low (1.3) | Grafana | Grafana Alerting Editors can edit destination of webhooks they did not create | — |
| 2025-11-19 | CVE-2025-41115 | Critical (10.0) | Grafana Enterprise | Incorrect privilege assignment | — |
| 2025-11-11 | CVE-2025-41116 | Low (2.1) | Grafana Databricks Datasource Plugin | Incorrect OAuth Passthrough in Grafana Databricks Datasource | — |
| 2025-11-11 | CVE-2025-3717 | Low (2.1) | Grafana Snowflake Datasource Plugin | Incorrect OAuth Passthrough in Grafana Snowflake Datasource | — |
| 2025-10-09 | CVE-2025-11539 | Critical (9.9) | Grafana Image Renderer Plugin | Arbitrary Code Execution in Grafana Image Renderer Plugin | — |
| 2025-09-19 | CVE-2025-10630 | Low (4.3) | Grafana Zabbix Plugin | Regex DoS in Zabbix Plugin | 2026-06-01 |
| 2025-08-04 | CVE-2025-8341 | Medium (6.1) | Grafana Infinity Plugin | SSRF in Infinity Plugin in Grafana | — |
| 2025-07-18 | CVE-2025-6197 | Medium (4.2) | Grafana | Open Redirect in Organization Switching in Grafana | — |
| 2025-07-18 | CVE-2025-6023 | High (7.6) | Grafana | XSS in Scripted Dashboards in Grafana | — |
| 2025-07-17 | CVE-2025-3415 | Medium (4.3) | Grafana | Information Disclosure in DingDing Integration in Grafana | — |
| 2025-06-17 | CVE-2025-1088 | Low (2.7) | Grafana | DoS in Dashboard Titles in Grafana | — |
| 2025-06-02 | CVE-2025-3260 | High (8.3) | Grafana | Authorization Bypass in Dashboard API in Grafana | — |
| 2025-06-02 | CVE-2025-3454 | Medium (5.0) | Grafana | Authorization Bypass in Data Source Proxy in Grafana | — |
| 2025-05-22 | CVE-2025-3580 | Medium (5.5) | Grafana | Privilege Escalation in Admin Management in Grafana | — |
| 2025-05-21 | CVE-2025-4123 | High (7.6) | Grafana | XSS in Frontend Plugins in Grafana | — |