Vulnerabilities > Grafana > Grafana > 7.2.0

DATE CVE VULNERABILITY TITLE RISK
2022-07-15 CVE-2022-31107 Incorrect Authorization vulnerability in multiple products
Grafana is an open-source platform for monitoring and observability.
network
high complexity
grafana netapp CWE-863
7.5
2022-03-21 CVE-2022-26148 Cleartext Storage of Sensitive Information vulnerability in multiple products
An issue was discovered in Grafana through 7.3.4, when integrated with Zabbix.
network
low complexity
grafana redhat CWE-312
7.5
2022-02-08 CVE-2022-21703 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana netapp fedoraproject CWE-352
8.8
2022-02-08 CVE-2022-21713 Authorization Bypass Through User-Controlled Key vulnerability in multiple products
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana netapp fedoraproject CWE-639
4.3
2022-02-08 CVE-2022-21702 Cross-site Scripting vulnerability in multiple products
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana netapp fedoraproject CWE-79
5.4
2022-01-18 CVE-2022-21673 Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana fedoraproject
4.3
2021-12-10 CVE-2021-43815 Path Traversal vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
grafana CWE-22
3.5
2021-12-10 CVE-2021-43813 Path Traversal vulnerability in Grafana
Grafana is an open-source platform for monitoring and observability.
network
low complexity
grafana CWE-22
4.0
2021-10-05 CVE-2021-39226 Improper Authentication vulnerability in multiple products
Grafana is an open source data visualization platform.
network
low complexity
grafana fedoraproject CWE-287
7.3
2021-03-22 CVE-2021-28148 Missing Authentication for Critical Function vulnerability in Grafana
One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication.
network
low complexity
grafana CWE-306
5.0