Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS. Join the discussion | CVE Database V5 | 09/17/2026, 20:47:01 UTC Added: 09/17/2026, 21:17:13 UTC |
0 A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin. Join the discussion | CVE Database V5 | 09/17/2026, 20:22:55 UTC Added: 09/17/2026, 20:47:37 UTC |
0 CVE-2026-17033 is a cross-site scripting (XSS) vulnerability in Grafana OSS that allows an authenticated attacker with Editor access or alert.instances.external:write permission to inject malicious JavaScript via a crafted external Alertmanager alert. The vulnerability arises because Grafana renders the alert.generatorURL directly without proper URL-scheme sanitization or a safe-protocol allowlist. When a user with read access clicks the 'See source' link, the attacker's script executes in the context of the user's Grafana session. Join the discussion | CVE Database V5 | 08/24/2026, 13:52:26 UTC Added: 08/24/2026, 14:08:11 UTC |
CVE-2026-17183 is a high-severity vulnerability in Grafana OSS where an authenticated user with permission to create or edit alert rules can bypass datasource query authorization. By marking an alert rule query as a server-side expression referencing a real datasource UID, the user can access data through Grafana's datasource credentials without proper permission. This incorrect authorization flaw can expose sensitive data to unauthorized users. Join the discussion | CVE Database V5 | 08/19/2026, 17:30:06 UTC Added: 08/19/2026, 17:43:12 UTC |
0 This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only. Join the discussion | CVE Database V5 | 08/17/2026, 21:28:17 UTC Added: 08/17/2026, 21:42:10 UTC |
0 The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled. Join the discussion | CVE Database V5 | 07/23/2026, 01:48:16 UTC Added: 07/23/2026, 15:08:37 UTC |
0 Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service. Join the discussion | CVE Database V5 | 07/15/2026, 00:00:00 UTC Added: 07/10/2026, 15:48:25 UTC |
0 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting). Join the discussion | CVE Database V5 | 07/10/2026, 14:59:35 UTC Added: 07/10/2026, 15:48:25 UTC |
0 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). Join the discussion | CVE Database V5 | 07/10/2026, 14:58:33 UTC Added: 07/10/2026, 15:48:26 UTC |
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations. Join the discussion | CVE Database V5 | 06/23/2026, 00:00:00 UTC Added: 04/15/2026, 15:31:52 UTC |
Showing 1 to 10 of 25 results