Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-41181 Source Traefik's error pages middleware inadvertently forwards sensitive authentication data like Authorization headers and cookies to separate error page services, even though these were only intended for the original backend service. |
Traefik | OS & platform | Medium | 06.06.2026 |
| CVE-2026-41174 Source Traefik's Kubernetes provider incorrectly bypasses namespace isolation when using Chain middleware, allowing attackers with CRD permissions in one namespace to access middleware objects from other namespaces. |
Traefik | OS & platform | Medium | 06.06.2026 |
| CVE-2026-44774 Source A vulnerability in Traefik's Kubernetes Gateway API provider allows users with HTTPRoute permissions to gain unauthorized access to the REST configuration interface and manipulate Traefik's configuration, bypassing intended security settings that should prevent such access. |
Traefik | OS & platform | Medium | 06.06.2026 |
| CVE-2026-53622 Source A vulnerability in Traefik's HTTP/3 implementation allows attackers to bypass client certificate authentication when wildcard hostnames or different letter casing are used, enabling access to protected backends without required certificates. |
Traefik | OS & platform | High | 06.06.2026 |
| CVE-2026-48491 Source A security vulnerability in Traefik allows attackers to bypass client certificate authentication when wildcard routers are configured with stricter TLS settings by exploiting another permissive SNI connection on the same endpoint. |
Traefik | OS & platform | High | 06.06.2026 |
| CVE-2026-48020 Source A vulnerability in Traefik's StripPrefix middleware allows attackers to bypass authentication by using paths containing '..' that get normalized to protected backend paths after the prefix is stripped. |
Traefik | OS & platform | High | 06.06.2026 |
| CVE-2021-39226 Source A critical security vulnerability in Grafana allows attackers to access and delete dashboard snapshots without authentication by using specific URL paths. |
Grafana | OS & platform | Critical | 06.06.2026 |
| CVE-2021-41174 Source A vulnerability in Grafana allows attackers to execute malicious JavaScript code through specially crafted URLs when users are unauthenticated and visit certain pages. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2021-41244 Source A vulnerability in Grafana allowed organization administrators to manage user roles in other organizations where they had no authority. This only affected installations with the fine-grained access control beta feature enabled and multiple organizations present. |
Grafana | OS & platform | Critical | 06.06.2026 |
| CVE-2021-43798 Source Grafana versions 8.0.0-beta1 through 8.3.0 contain a path traversal vulnerability that allows attackers to access local server files through specific plugin URLs. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2021-43813 Source Grafana applications between versions 5.0.0 and 8.3.1 contain a security vulnerability that allows authenticated users to read certain markdown files through directory traversal attacks. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2021-43815 Source Grafana contains a security vulnerability that allows authenticated users to read arbitrary CSV files through directory traversal, but only when the TestData DB data source is enabled. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-21673 Source A flaw in Grafana allows API token holders to access data they shouldn't have permission for by forwarding the OAuth identity of the most recently logged-in user. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-21702 Source Grafana versions up to 8.3.4 contain a Cross-Site Scripting vulnerability where attackers can inject malicious HTML code through compromised data sources or plugins. Authenticated users could be tricked into executing malicious code through specially crafted links. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-21703 Source Grafana dashboards are vulnerable to Cross-Site Request Forgery attacks where attackers can trick authenticated users into granting them high privileges. All versions from 3.0-beta1 onwards are affected, allowing privilege escalation by deceiving administrators. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-21713 Source Grafana versions from 5.0.0-beta1 onwards have a vulnerability in the Teams API that allows authenticated attackers to access team data they should not have permission to view. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-24812 Source A vulnerability in Grafana Enterprise allows attackers to gain elevated privileges when the fine-grained access control beta feature is enabled and multiple API keys with different roles are used. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2022-29170 Source Grafana Enterprise has a vulnerability that allows attackers to bypass network restrictions for data sources by using HTTP redirects to access servers that should be blocked. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-31097 Source Grafana versions 8.0 and later contain a stored Cross-Site Scripting vulnerability in the Unified Alerting feature. Attackers can exploit this to escalate their privileges from Editor to Admin by tricking authenticated administrators into clicking a malicious link. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2022-31107 Source A vulnerability in Grafana's OAuth authentication allows malicious users to take over existing user accounts. All Grafana versions from 5.3 onwards are affected and should be updated immediately. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2022-31123 Source A vulnerability in Grafana allows attackers to bypass plugin signature verification and install malicious plugins even when unsigned plugins should be blocked by security settings. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-31130 Source A vulnerability in Grafana allows certain plugins to intercept user authentication tokens, potentially exposing sensitive login credentials. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-35957 Source A vulnerability in Grafana allows administrators to escalate their privileges to Server Admin when Auth Proxy authentication is used. Attackers can create a fake datasource pointing to localhost that contains admin user credentials to gain elevated access. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-36062 Source A flaw in Grafana's role-based access control allows users with Editor or Viewer permissions to access folders and dashboards that should only be available to Administrators. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-39201 Source A security vulnerability in Grafana allows plugins to receive user authentication cookies, which occurs under certain conditions at data source and plugin proxy endpoints. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-39229 Source Grafana has an authentication flaw where an attacker can prevent legitimate users from logging in by registering a username that matches another user's email address. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-39306 Source Grafana has a vulnerability in invitation links that allows attackers to register with arbitrary usernames or email addresses to gain unauthorized access to organizations. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-39307 Source Grafana applications up to version 9.x have a vulnerability that allows attackers to discover which usernames or email addresses exist in the system by abusing the password reset function. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-39324 Source In Grafana, users with Viewer permissions can inject arbitrary URLs when creating dashboard snapshots, which are then displayed to other users as trusted links to the original dashboard. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2022-39328 Source A race condition in Grafana allows unauthenticated users to query protected endpoints because under heavy load HTTP requests can receive incorrect authentication middleware from other calls. |
Grafana | OS & platform | Critical | 06.06.2026 |
| CVE-2022-41912 Source A vulnerability in Grafana Enterprise allows attackers to escalate their privileges by manipulating SAML responses containing multiple assertions. Only unsigned SAML documents with at least one signed assertion are affected, potentially allowing attackers to gain administrative access. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2022-23498 Source A flaw in Grafana Enterprise allows users to receive other users' session cookies when datasource query caching is enabled, potentially granting unauthorized access to other user accounts. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2022-23552 Source A vulnerability in Grafana's GeoMap plugin allows users with Editor permissions to inject malicious JavaScript code through SVG files, which then executes in other users' browsers and can be exploited for privilege escalation. |
Grafana | OS & platform | High | 06.06.2026 |
| CVE-2023-22462 Source A security vulnerability in Grafana's Text plugin allows users with Editor permissions to store malicious JavaScript code that executes when Admin users edit the panel and click specific options. |
Grafana | OS & platform | Medium | 06.06.2026 |
| CVE-2021-29622 Source Prometheus monitoring software contains a vulnerability that allows attackers to redirect users to arbitrary external websites through specially crafted URLs, which could be exploited for phishing attacks. |
Prometheus | OS & platform | Medium | 06.06.2026 |
| CVE-2022-46146 Source A vulnerability in Prometheus allows attackers to bypass authentication if they have access to hashed passwords by manipulating the internal cache used for password verification. |
Prometheus | OS & platform | High | 06.06.2026 |
| CVE-2026-40179 Source A security vulnerability in the Prometheus web interface allows attackers to inject malicious JavaScript code through crafted metric names, which then executes in users' browsers when they hover over charts or browse metrics. |
Prometheus | OS & platform | Medium | 06.06.2026 |
| CVE-2026-42151 Source A vulnerability in Prometheus exposes Azure AD OAuth secrets in plaintext through an HTTP API when users can access the configuration endpoint. |
Prometheus | OS & platform | High | 06.06.2026 |
| CVE-2026-42154 Source A vulnerability in Prometheus allows attackers to cause excessive memory allocation and crash the service by sending crafted requests to the remote read endpoint. |
Prometheus | OS & platform | High | 06.06.2026 |
| CVE-2026-44903 Source A security vulnerability in Prometheus allows attackers to inject malicious JavaScript code into the legacy web interface when they can inject crafted metrics, potentially enabling data theft or server shutdown. |
Prometheus | OS & platform | Medium | 06.06.2026 |
| CVE-2023-45672 Source A security vulnerability in Frigate video surveillance software allows attackers to execute malicious code on the server by sending specially crafted configuration data through the web interface. |
Frigate | Self-hosted apps | High | 06.06.2026 |
| CVE-2023-45671 Source A security vulnerability in Frigate video surveillance software allows cross-site scripting attacks through improper handling of camera names in API endpoints, enabling attackers to execute malicious JavaScript code in user browsers. |
Frigate | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-45670 Source Frigate video surveillance software has a vulnerability where attackers can modify server configuration through malicious websites when authenticated users click specially crafted links. |
Frigate | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2024-32874 Source A vulnerability in Frigate video security software allows attackers with access to the application to cause a denial-of-service attack by uploading files with extremely long Unicode names, which overloads the CPU through expensive Unicode normalization processing. |
Frigate | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2025-62382 Source A vulnerability in Frigate video surveillance software allows authenticated users to read arbitrary files from the server by abusing the export function and providing a malicious file path as thumbnail source. |
Frigate | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-33126 Source A security vulnerability in Frigate allows attackers to abuse the server to send HTTP requests to internal network resources, as an API endpoint accepts URLs without proper validation. |
Frigate | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-33125 Source A vulnerability in Frigate software allows unauthenticated users to delete administrator and other user accounts, potentially causing service disruption and data loss. |
Frigate | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-33124 Source Frigate allows authenticated users to change their password without confirming the current password and doesn't invalidate existing sessions. Attackers can permanently take over accounts when sessions are compromised. |
Frigate | Self-hosted apps | Low | 06.06.2026 |
| CVE-2026-25643 Source A critical security vulnerability in Frigate software allows administrators or attackers on unprotected installations to execute arbitrary system commands through video stream configuration, potentially gaining complete control over the system. |
Frigate | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-33469 Source A vulnerability in Frigate software allows authenticated non-admin users to retrieve the complete configuration file containing sensitive data like camera passwords and other secrets through an API endpoint. |
Frigate | Self-hosted apps | Medium | 06.06.2026 |