CVE-2023-2801
A flaw was found in grafana. This issue occurs when sending an API call to the /ds/query or public dashboard query endpoint that has mixed queries, such as having two or more distinct data sources in ...
Continue Reading
June 30, 2023
Access Control Bypass
github.com/grafana/grafana is vulnerable to Access Control Bypass. The vulnerability exists due to a lack of write authorization checks in `authorization.go`, which allows an attacker with the viewer ...
Continue Reading
June 30, 2023
Denial Of Service (DoS)
github.com/grafana/grafana is vulnerable to Denial Of Service (DoS). The vulnerability exists due to executing concurrent mixed queries through the `executeConcurrentQueries` function of `query.go`, w ...
Continue Reading
June 30, 2023
Moderate: sqlite security update
SQLite is a C library that implements an SQL database engine. A large subset of SQL92 is supported. A complete database is stored in a single disk file. The API is designed for convenience and ease of ...
Continue Reading
June 29, 2023
Missing Authorization
github.com/mattermost/mattermost-server is vulnerable to Missing Authorization. The vulnerability exists because the library does not verify whether the requestor is a system admin or not before allow ...
Continue Reading
June 29, 2023
Moderate: libvirt security update
The libvirt library contains a C API for managing and interacting with the virtualization capabilities of Linux and other operating systems. In addition, libvirt provides tools for remote management o ...
Continue Reading
June 26, 2023
CVE-2023-1619
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high privileges to DoS the device by sending a malformed packet.Read More ...
Continue Reading
June 26, 2023