<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:58:29.013709+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07743</id>
    <title>bdu:2026-07743</title>
    <updated>2026-10-02T14:58:29.027348+00:00</updated>
    <content>bdu:2026-07743</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07743"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2025-3454</id>
    <title>BIT-grafana-2025-3454</title>
    <updated>2026-10-02T14:58:29.027389+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.</p>
<p>Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.</p>
<p>The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2025-3454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0344</id>
    <title>certfr-2025-avi-0344 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles permettent à un attaquant de provoquer une injectio…</title>
    <updated>2026-10-02T14:58:29.027426+00:00</updated>
    <content>certfr-2025-avi-0344</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0344"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-242312</id>
    <title>EUVD-2026-242312</title>
    <updated>2026-10-02T14:58:29.027444+00:00</updated>
    <content>EUVD-2026-242312</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-242312"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-3454</id>
    <title>fkie_cve-2025-3454</title>
    <updated>2026-10-02T14:58:29.027456+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.</p>
<p>Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.</p>
<p>The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-3454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9j65-rv5x-4vrf</id>
    <title>GHSA-9j65-rv5x-4vrf — Grafana's datasource proxy API allows authorization checks to be bypassed</title>
    <updated>2026-10-02T14:58:29.027478+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path.</p>
<p>Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources.</p>
<p>The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9j65-rv5x-4vrf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15052-1</id>
    <title>openSUSE-SU-2025:15052-1 — grafana-11.5.4-1.1 on GA media</title>
    <updated>2026-10-02T14:58:29.027501+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-11.5.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15052-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/sca-2026-0002</id>
    <title>SCA-2026-0002 — Vulnerabilities affecting SICK Incoming Goods Suite</title>
    <updated>2026-10-02T14:58:29.027518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01 A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are similarly affected Organization isolation boundaries remain intact. The vulnerability only affects dashboard access and does not grant access to datasources. The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript. A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permis…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/sca-2026-0002"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01985-1</id>
    <title>SUSE-SU-2025:01985-1 — Security update 4.3.15 for Multi-Linux Manager Server</title>
    <updated>2026-10-02T14:58:29.027564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 4.3.15 for Multi-Linux Manager Server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01985-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3454</id>
    <title>UBUNTU-CVE-2025-3454</title>
    <updated>2026-10-02T14:58:29.027584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-3454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0867</id>
    <title>WID-SEC-W-2025-0867 — Grafana: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:58:29.027603+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder Informationen auszuspähen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0867"/>
  </entry>
</feed>
