Vulnerability Name CVE Severity
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-43798) CVE-2021-43798
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-43813) CVE-2021-43813
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-43815) CVE-2021-43815
Grafana Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2022-32275) CVE-2022-32275
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-12099) CVE-2018-12099
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-18623) CVE-2018-18623
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-18624) CVE-2018-18624
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-18625) CVE-2018-18625
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2018-1000816) CVE-2018-1000816
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-13068) CVE-2019-13068
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11110) CVE-2020-11110
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12052) CVE-2020-12052
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-12245) CVE-2020-12245
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-13430) CVE-2020-13430
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-24303) CVE-2020-24303
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-41174) CVE-2021-41174
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-21702) CVE-2022-21702
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-23552) CVE-2022-23552
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-31097) CVE-2022-31097
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-39324) CVE-2022-39324
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-0507) CVE-2023-0507
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-0594) CVE-2023-0594
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-1410) CVE-2023-1410
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-22462) CVE-2023-22462
Grafana Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-41117) CVE-2025-41117
Grafana Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2024-9264) CVE-2024-9264
Grafana Improper Preservation of Permissions Vulnerability (CVE-2022-36062) CVE-2022-36062
Grafana Improper Synchronization Vulnerability (CVE-2023-2801) CVE-2023-2801
Grafana Improper Verification of Cryptographic Signature Vulnerability (CVE-2022-31123) CVE-2022-31123
Grafana Incorrect Authorization Vulnerability (CVE-2021-28146) CVE-2021-28146
Grafana Incorrect Authorization Vulnerability (CVE-2022-21713) CVE-2022-21713
Grafana Incorrect Authorization Vulnerability (CVE-2022-31107) CVE-2022-31107
Grafana Incorrect Authorization Vulnerability (CVE-2023-6152) CVE-2023-6152
Grafana Incorrect Authorization Vulnerability (CVE-2026-21721) CVE-2026-21721
Grafana Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-27962) CVE-2021-27962
Grafana Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2026-21727) CVE-2026-21727
Grafana Incorrect Privilege Assignment Vulnerability (CVE-2025-41115) CVE-2025-41115
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2019-15635) CVE-2019-15635
Grafana Insufficiently Protected Credentials Vulnerability (CVE-2022-31130) CVE-2022-31130
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2019-15043) CVE-2019-15043
Grafana Missing Authentication for Critical Function Vulnerability (CVE-2022-28660) CVE-2022-28660
Grafana Missing Authorization Vulnerability (CVE-2023-2183) CVE-2023-2183
Grafana Open Redirect (CVE-2025-4123) CVE-2025-4123
Grafana Other Vulnerability (CVE-2021-28147) CVE-2021-28147
Grafana Out-of-bounds Write Vulnerability (CVE-2026-27879) CVE-2026-27879
Grafana Out-of-bounds Write Vulnerability (CVE-2026-27880) CVE-2026-27880
Grafana Plugin Dir Traversal (CVE-2021-43798) CVE-2021-43798
Grafana Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-13379) CVE-2020-13379
Grafana Signature Verification Vulnerability (CVE-2020-27846) CVE-2020-27846
Grafana Snapshot Authentication Bypass (CVE-2021-39226) CVE-2021-39226
Grafana Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2026-21725) CVE-2026-21725
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-21720) CVE-2026-21720
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-28375) CVE-2026-28375
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-33375) CVE-2026-33375
Grafana Uncontrolled Resource Consumption Vulnerability (CVE-2026-33378) CVE-2026-33378
Grafana URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29170) CVE-2022-29170
Grails database console
Grandnode Path Traversal (CVE-2019-12276) CVE-2019-12276
GraphiQL Explorer/Playground Enabled
GraphQL Alias Overloading Allowed: Potential Denial of Service Vulnerability
GraphQL Array-based Query Batching Allowed: Potential Batching Attack Vulnerability
GraphQL Circular-Query via Introspection Allowed: Potential DoS Vulnerability
GraphQL Field Suggestions Enabled
GraphQL Introspection Query Enabled
GraphQL Non-JSON Mutations over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over GET: Potential CSRF Vulnerability
GraphQL Non-JSON Queries over POST: Potential CSRF Vulnerability
GraphQL Unauthenticated Mutation Detected
GraphQL Unhandled Error Leakage
Grav CMS Unauthenticated RCE (CVE-2021-21425) CVE-2021-21425
GSAP CVE-2020-28478 Vulnerability (CVE-2020-28478) CVE-2020-28478
Gunicorn Improper Neutralization of CRLF Sequences ('CRLF Injection') Vulnerability (CVE-2018-1000164) CVE-2018-1000164
H2 console publicly accessible
Hadoop cluster web interface
Hadoop YARN ResourceManager publicly accessible