CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is: `<grafana_host_url>/public/plugins//`, where is the plugin ID for any installed plugin. At no time has Grafana Cloud been vulnerable. Users are advised to upgrade to patched versions 8.0.7, 8.1.8, 8.2.7, or 8.3.1. The GitHub Security Advisory contains more information about vulnerable URL paths, mitigation, and the disclosure timeline. |
Considered by the maintainers a bug scenario experienced rather than a vulnerability. |
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection. |
ASP.NET Core Denial of Service Vulnerability |
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability |
ASP.NET Core Security Feature Bypass Vulnerability |
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability |
PowerShell Information Disclosure Vulnerability |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Visual Studio Code Jupyter Extension Spoofing Vulnerability |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
Microsoft Windows Defender Elevation of Privilege Vulnerability |
Windows SmartScreen Security Feature Bypass Vulnerability |
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability |
Windows DWM Core Library Elevation of Privilege Vulnerability |
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
Microsoft Dynamics 365 Sales Spoofing Vulnerability |