Vulnerability Name CVE Severity
Grafana Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2024-10452) CVE-2024-10452
Grafana avatar SSRF CVE-2020-13379
Grafana Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-12458) CVE-2020-12458
Grafana Cleartext Storage of Sensitive Information Vulnerability (CVE-2022-26148) CVE-2022-26148
Grafana Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2022-39328) CVE-2022-39328
Grafana Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2022-21703) CVE-2022-21703
Grafana CVE-2021-27358 Vulnerability (CVE-2021-27358) CVE-2021-27358
Grafana CVE-2022-39201 Vulnerability (CVE-2022-39201) CVE-2022-39201
Grafana CVE-2022-39307 Vulnerability (CVE-2022-39307) CVE-2022-39307
Grafana CVE-2023-1387 Vulnerability (CVE-2023-1387) CVE-2023-1387
Grafana CVE-2023-4399 Vulnerability (CVE-2023-4399) CVE-2023-4399
Grafana CVE-2023-4822 Vulnerability (CVE-2023-4822) CVE-2023-4822
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-19039) CVE-2018-19039
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-19499) CVE-2019-19499
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-12459) CVE-2020-12459
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-21673) CVE-2022-21673
Grafana Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2022-23498) CVE-2022-23498
Grafana Externally Controlled Reference to a Resource in Another Sphere Vulnerability (CVE-2021-41244) CVE-2021-41244
Grafana Improper Authentication Vulnerability (CVE-2018-15727) CVE-2018-15727
Grafana Improper Authentication Vulnerability (CVE-2021-28148) CVE-2021-28148
Grafana Improper Authentication Vulnerability (CVE-2021-39226) CVE-2021-39226
Grafana Improper Authentication Vulnerability (CVE-2022-32276) CVE-2022-32276
Grafana Improper Authentication Vulnerability (CVE-2022-39229) CVE-2022-39229
Grafana Improper Input Validation Vulnerability (CVE-2022-39306) CVE-2022-39306
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-43798) CVE-2021-43798
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-43813) CVE-2021-43813
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-43815) CVE-2021-43815
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-32275) CVE-2022-32275
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-12099) CVE-2018-12099
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-18623) CVE-2018-18623
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-18624) CVE-2018-18624
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-18625) CVE-2018-18625
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1000816) CVE-2018-1000816
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-13068) CVE-2019-13068
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11110) CVE-2020-11110
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12052) CVE-2020-12052
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12245) CVE-2020-12245
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13430) CVE-2020-13430
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-24303) CVE-2020-24303
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41174) CVE-2021-41174
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-21702) CVE-2022-21702
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-23552) CVE-2022-23552
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-31097) CVE-2022-31097
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-39324) CVE-2022-39324
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-0507) CVE-2023-0507
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-0594) CVE-2023-0594
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-1410) CVE-2023-1410
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-22462) CVE-2023-22462
Grafana Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2024-9264) CVE-2024-9264
Grafana Improper Preservation of Permissions Vulnerability (CVE-2022-36062) CVE-2022-36062
Grafana Improper Synchronization Vulnerability (CVE-2023-2801) CVE-2023-2801
Grafana Improper Verification of Cryptographic Signature Vulnerability (CVE-2022-31123) CVE-2022-31123
Grafana Incorrect Authorization Vulnerability (CVE-2021-28146) CVE-2021-28146
Grafana Incorrect Authorization Vulnerability (CVE-2022-21713) CVE-2022-21713
Grafana Incorrect Authorization Vulnerability (CVE-2022-31107) CVE-2022-31107
Grafana Incorrect Authorization Vulnerability (CVE-2023-6152) CVE-2023-6152
Grafana Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-27962) CVE-2021-27962
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635) CVE-2019-15635
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2022-31130) CVE-2022-31130
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2019-15043) CVE-2019-15043
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2022-28660) CVE-2022-28660
Grafana Missing Authorization Vulnerability (CVE-2023-2183) CVE-2023-2183
Grafana Other Vulnerability (CVE-2021-28147) CVE-2021-28147
Grafana Plugin Dir Traversal (CVE-2021-43798) CVE-2021-43798
Grafana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-13379) CVE-2020-13379
Grafana Signature Verification Vulnerability (CVE-2020-27846) CVE-2020-27846
Grafana Snapshot Authentication Bypass (CVE-2021-39226) CVE-2021-39226
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170) CVE-2022-29170
Grails database console
Grandnode Path Traversal (CVE-2019-12276) CVE-2019-12276
GraphiQL Explorer/Playground Enabled
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
GraphQL Field Suggestions Enabled