Known vulnerabilities in Grafana - page 5

Software: Grafana
Software CPE: cpe:2.3:a:grafana_labs:grafana:*:*:*:*:*:*:*:*
Total vulnerabilities: 118
Public exploits: 11
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Grafana Grafana is affected by 118 known vulnerabilities: 7 high, 43 medium, 68 low Critical High Medium Low

Vulnerabilities (118)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64430 - Incorrect Authorization
CVE-2021-41244
CWE-863 Medium
No
No
8.2.4 16.06.2022 SB2021111513
SB2022062026
SB2022102094
and 5 more
#VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43815
CWE-22 Low
No
No
7.5.12, 8.3.2 15.06.2022 SB2021121022
SB2022062026
SB2022102094
and 8 more
#VU64402 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21673
CWE-200 Low
No
No
7.5.13, 8.3.4 15.06.2022 SB2022061623
SB2022062026
SB2022081215
and 12 more
#VU64400 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-32275
CWE-22 Medium
Available
No
8.4.5 15.06.2022 SB2022061622
SB2024022823
SB2024080829
#VU64399 - Cross-Site Request Forgery (CSRF)
CVE-2022-21703
CWE-352 Medium
No
No
7.5.15, 8.3.5 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
7.5.15, 8.3.5 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64394 - Authorization Bypass Through User-Controlled Key
CVE-2022-21713
CWE-639 Low
No
No
7.5.15, 8.3.5 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 13 more
#VU64388 - Exposure of sensitive information to an unauthorized actor
CVE-2022-26148
CWE-200 Low
No
No
7.3.5 15.06.2022 SB2022061620
SB2023061619
SB2024022823
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
9.0.3 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU63461 - Improper input validation
CVE-2022-29170
CWE-20 Low
No
No
7.5.16, 8.5.3 19.05.2022 SB2022051916
SB2024012352
SB2024012403
and 3 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
9.0.3 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU62283 - Permissions, Privileges, and Access Controls
CVE-2022-24812
CWE-264 Medium
No
No
8.4.6 13.04.2022 SB2022041315
SB2024022823
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
9.0.3 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Available
Exploited
8.0.7, 8.1.8, 8.2.7, 8.3.1 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more
#VU57926 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41174
CWE-79 Low
Available
No
8.2.3 03.11.2021 SB2021110312
SB2021110517
SB2022062026
and 4 more
#VU57320 - Improper Access Control
CVE-2021-39226
CWE-284 Medium
Available
Exploited
7.5.11, 8.1.6 12.10.2021 SB2021101262
SB2021101320
SB2021101321
and 22 more
#VU55287 - NULL Pointer Dereference
CVE-2021-36222
CWE-476 Medium
No
No
8.1.0 25.07.2021 SB2021072501
SB2021072502
SB2021080601
and 24 more
#VU51581 - Improper Access Control
CVE-2021-28147
CWE-284 Medium
No
No
6.7.6, 7.3.10, 7.4.5 19.03.2021 SB2021031903
SB2021081235
SB2021081237
and 3 more
#VU51580 - Improper Access Control
CVE-2021-28146
CWE-284 Medium
No
No
7.4.5 19.03.2021 SB2021031903
SB2021081235
SB2021081237
and 3 more
#VU51579 - Improper Privilege Management
CVE-2021-27962
CWE-269 Low
No
No
7.3.10, 7.4.5 19.03.2021 SB2021031903
SB2021081235
SB2021081237
and 3 more


Showing elements 81 - 100 out of 118