Direct Vulnerabilities

Known vulnerabilities in the grafana package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Inefficient Regular Expression Complexity

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Cross-site Scripting (XSS)

*
  • H
Directory Traversal

*
  • M
Incorrect Authorization

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • H
Information Exposure Through Caching

*
  • H
Missing Authentication for Critical Function

*
  • M
Information Exposure Through Caching

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Link Following

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Certificate Validation

*
  • M
Improper Validation of Specified Quantity in Input

*
  • H
Excessive Platform Resource Consumption within a Loop

<0:10.2.6-28.el10_2.5
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Link Following

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • M
Improper Certificate Validation

*
  • M
CRLF Injection

*
  • M
Improper Certificate Validation

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
External Control of Assumed-Immutable Web Parameter

*
  • M
Cross-site Scripting (XSS)

*
  • M
Operator Precedence Logic Error

*
  • M
Cross-site Scripting (XSS)

<0:10.2.6-26.el10_0
  • H
Cross-site Scripting (XSS)

<0:10.2.6-26.el10_0
  • H
Improper Validation of Unsafe Equivalence in Input

<0:10.2.6-26.el10_0
  • H
Cross-site Scripting (XSS)

<0:10.2.6-26.el10_0
  • H
Cross-site Scripting (XSS)

<0:10.2.6-26.el10_0
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0:10.2.6-26.el10_0
  • H
Excessive Platform Resource Consumption within a Loop

<0:10.2.6-26.el10_0
  • M
Directory Traversal

*
  • M
Privilege Defined With Unsafe Actions

<0:10.2.6-26.el10_0
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-26.el10_0
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-26.el10_0
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-26.el10_0
  • H
Improper Certificate Validation

<0:10.2.6-26.el10_0
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0:10.2.6-26.el10_0
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-26.el10_0
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-26.el10_0
  • M
Improper Handling of Case Sensitivity

*
  • H
Unchecked Input for Loop Condition

<0:10.2.6-26.el10_0
  • H
Improper Validation of Unsafe Equivalence in Input

<0:10.2.6-26.el10_0
  • M
Permissive Whitelist

<0:10.2.6-26.el10_0
  • H
Creation of Immutable Text Using String Concatenation

<0:10.2.6-26.el10_0
  • M
Uncaught Exception

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-28.el10_2.4
  • M
Information Exposure Through Caching

*
  • M
Deadlock

*
  • M
Deadlock

*
  • L
HTTP Request Smuggling

*
  • L
HTTP Request Smuggling

*
  • M
Missing Handler

*
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Information Exposure Through Caching

*
  • M
Detection of Error Condition Without Action

*
  • M
Improper Update of Reference Count

*
  • M
Inefficient Regular Expression Complexity

*
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-28.el10_2.5
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0:10.2.6-28.el10_2.5
  • H
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0:10.2.6-28.el10_2.5
  • M
Resource Exhaustion

*
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-28.el10_2.5
  • H
Cross-site Scripting (XSS)

<0:10.2.6-28.el10_2.5
  • H
Creation of Immutable Text Using String Concatenation

<0:10.2.6-28.el10_2.5
  • H
Excessive Platform Resource Consumption within a Loop

<0:10.2.6-28.el10_2.5
  • H
Unchecked Input for Loop Condition

<0:10.2.6-28.el10_2.5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Improper Validation of Syntactic Correctness of Input

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
XML Injection

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Expression Language Injection

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Permissive Whitelist

<0:10.2.6-28.el10_2.4
  • M
Privilege Defined With Unsafe Actions

<0:10.2.6-28.el10_2.4
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-28.el10_2.4
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-28.el10_2.4
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Authentication Bypass

*
  • M
Authentication Bypass

*
  • M
Improper Authentication

*
  • M
Improper Authentication

*
  • M
CVE-2022-39201

*
  • M
CVE-2022-39201

*
  • M
Insufficiently Protected Credentials

*
  • M
Insufficiently Protected Credentials

*
  • M
Improper Verification of Cryptographic Signature

*
  • M
Improper Verification of Cryptographic Signature

*
  • H
Improper Authentication

*
  • H
Improper Authentication

*
  • M
Open Redirect

*
  • M
Deserialization of Untrusted Data

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Cross-site Scripting (XSS)

<0:10.2.6-27.el10_2
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Improper Handling of Case Sensitivity

*
  • M
Improper Authentication

*
  • M
Origin Validation Error

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Verification of Source of a Communication Channel

*
  • H
Improper Validation of Unsafe Equivalence in Input

<0:10.2.6-27.el10_2
  • H
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Cross-site Scripting (XSS)

*
  • M
External Control of Assumed-Immutable Web Parameter

*
  • M
Directory Traversal

*
  • M
Improper Output Neutralization for Logs

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Uncontrolled Recursion

*
  • L
Missing Release of Resource after Effective Lifetime

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • M
Excessive Platform Resource Consumption within a Loop

<0:10.2.6-24.el10_0
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Use of a Non-reentrant Function in a Concurrent Context

*
  • M
Insufficient Granularity of Access Control

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Least Privilege Violation

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • H
Improper Validation of Syntactic Correctness of Input

<0:10.2.6-25.el10_2
  • H
Multiple Locks of a Critical Resource

<0:10.2.6-26.el10_2
  • M
Time-of-check Time-of-use (TOCTOU)

<0:10.2.6-26.el10_2
  • H
Information Exposure

<0:10.2.6-26.el10_2
  • M
Time-of-check Time-of-use (TOCTOU)

<0:10.2.6-24.el10_0
  • H
Multiple Locks of a Critical Resource

<0:10.2.6-24.el10_0
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-24.el10_0
  • M
Origin Validation Error

*
  • M
Out-of-bounds Write

*
  • H
Multiple Locks of a Critical Resource

<0:10.2.6-25.el10_1
  • M
Time-of-check Time-of-use (TOCTOU)

<0:10.2.6-25.el10_1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Information Exposure

<0:10.2.6-23.el10_0
  • M
HTTP Request Smuggling

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Out-of-bounds Write

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • H
Information Exposure

<0:10.2.6-24.el10_1
  • H
Improper Validation of Syntactic Correctness of Input

<0:10.2.6-22.el10_0
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Insufficient Compartmentalization

*
  • L
Incorrect Privilege Assignment

*
  • M
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • H
Improper Validation of Unsafe Equivalence in Input

*
  • M
Excessive Platform Resource Consumption within a Loop

*
  • M
Cross-site Scripting (XSS)

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Validation of Syntactic Correctness of Input

<0:10.2.6-23.el10_1
  • H
Unchecked Input for Loop Condition

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • M
Cleartext Storage of Sensitive Information

*
  • M
Unchecked Input for Loop Condition

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Cleartext Storage of Sensitive Information

*
  • M
Cleartext Storage of Sensitive Information

*
  • M
Cross-site Request Forgery (CSRF)

*
  • M
Cross-site Request Forgery (CSRF)

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
External Control of Assumed-Immutable Web Parameter

*
  • M
External Control of Assumed-Immutable Web Parameter

*
  • H
Improper Certificate Validation

*
  • H
Excessive Platform Resource Consumption within a Loop

<0:10.2.6-21.el10_0
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-21.el10_0
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-21.el10_0
  • M
Improper Certificate Validation

<0:10.2.6-21.el10_0
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • H
Authorization Bypass Through User-Controlled Key

<0:10.2.6-20.el10_0
  • H
Excessive Platform Resource Consumption within a Loop

<0:10.2.6-22.el10_1
  • M
Improper Certificate Validation

<0:10.2.6-22.el10_1
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-22.el10_1
  • H
Allocation of Resources Without Limits or Throttling

<0:10.2.6-22.el10_1
  • H
Authorization Bypass Through User-Controlled Key

<0:10.2.6-22.el10_1
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • M
Resource Exhaustion

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Server-Side Request Forgery (SSRF)

*
  • M
Deserialization of Untrusted Data

*
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Open Redirect

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Out-of-bounds Read

*
  • M
Improper Input Validation

*
  • M
Open Redirect

*
  • M
Open Redirect

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • H
Improper Handling of Unexpected Data Type

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Certificate Validation

*
  • M
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • H
Arbitrary Code Injection

*
  • M
Use of Insufficiently Random Values

*
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-21.el10_1
  • M
Allocation of Resources Without Limits or Throttling

<0:10.2.6-19.el10_0
  • M
Integer Overflow or Wraparound

*
  • M
Creation of Immutable Text Using String Concatenation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Output Neutralization for Logs

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Expected Behavior Violation

*
  • M
Expected Behavior Violation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Inefficient Regular Expression Complexity

*
  • L
Open Redirect

*
  • L
Authorization Bypass Through User-Controlled Key

*
  • M
Insufficiently Protected Credentials

*
  • M
Insufficient Compartmentalization

*
  • M
Inefficient Regular Expression Complexity

*
  • M
CVE-2025-4673

*
  • H
Cross-site Scripting (XSS)

*
  • L
Improper Input Validation

*
  • L
Improper Input Validation

*
  • M
HTTP Request Smuggling

<0:10.2.6-18.el10_0
  • M
Origin Validation Error

*
  • M
Exposed Dangerous Method or Function

*
  • M
Improper Access Control

*
  • M
Arbitrary Code Injection

*
  • M
Cross-site Scripting (XSS)

*
  • L
Information Exposure

*
  • L
Improper Handling of Exceptional Conditions

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Improper Input Validation

*
  • M
Incomplete Filtering of Special Elements

*
  • M
CRLF Injection

*
  • M
Information Exposure

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Cross-site Scripting (XSS)

*
  • M
Information Exposure

*
  • H
Cross-site Scripting (XSS)

<0:10.2.6-17.el10_0
  • H
Asymmetric Resource Consumption (Amplification)

<0:10.2.6-15.el10_0
  • H
Resource Exhaustion

*
  • H
Resource Exhaustion

*
  • H
Resource Exhaustion

*
  • H
Improper Validation of Syntactic Correctness of Input

*
  • M
Resource Exhaustion

*
  • M
Directory Traversal

*
  • M
Directory Traversal

*
  • H
Resource Exhaustion

*
  • H
Resource Exhaustion

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Buffer Overflow

*
  • M
Buffer Overflow

*
  • M
Buffer Overflow

*
  • M
Integer Overflow or Wraparound

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • L
Improper Input Validation

*
  • L
Improper Validation of Array Index

*
  • L
Improper Validation of Array Index

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Arbitrary Code Injection

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Resource Exhaustion

*
  • M
Out-of-bounds Read

*
  • M
Improper Certificate Validation

*
  • L
Race Condition

*
  • L
Race Condition

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • M
Resource Exhaustion

*
  • L
Resource Exhaustion

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • L
Directory Traversal

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Integer Overflow or Wraparound

*
  • M
Integer Overflow or Wraparound

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Race Condition

*
  • M
Race Condition

*
  • M
Race Condition

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • L
Cross-site Scripting (XSS)

*
  • L
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • M
Incorrect Permission Assignment for Critical Resource

*
  • L
External Control of File Name or Path

*
  • L
External Control of File Name or Path

*
  • M
External Control of File Name or Path

*
  • L
Open Redirect

*
  • L
Open Redirect

*
  • M
Open Redirect

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • H
Resource Exhaustion

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Arbitrary Code Injection

*
  • L
Arbitrary Code Injection

*
  • M
Improper Privilege Management

*
  • M
Open Redirect

*
  • M
Open Redirect

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Incorrect Privilege Assignment

*
  • M
Incorrect Privilege Assignment

*
  • M
External Control of File Name or Path

*
  • M
External Control of File Name or Path

*
  • M
External Control of File Name or Path

*
  • M
Out-of-Bounds

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Out-of-Bounds

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Incorrect Authorization

*
  • M
Incorrect Authorization

*
  • L
Resource Exhaustion

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • H
Improper Authentication

*
  • L
Information Exposure

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Improper Authentication

*
  • M
Improper Authentication

*
  • M
Improper Authentication

*
  • L
Cross-site Scripting (XSS)

*
  • L
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • L
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Improper Input Validation

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Input Validation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • H
Authorization Bypass Through User-Controlled Key

*
  • H
Authorization Bypass Through User-Controlled Key

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Authorization Bypass Through User-Controlled Key

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • H
Server-Side Request Forgery (SSRF)

*
  • H
Cross-site Scripting (XSS)

*
  • H
Cross-site Scripting (XSS)

*
  • M
Arbitrary Code Injection

*
  • M
Arbitrary Code Injection

*
  • M
Missing Synchronization

*
  • M
Missing Synchronization

*
  • M
Improper Access Control

*
  • M
Improper Access Control

*
  • M
Incorrect Calculation

*
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

*
  • M
Incorrect Calculation

*
  • M
Information Exposure

*
  • M
Information Exposure

*
  • M
Incorrect Calculation

*
  • M
Cross-site Scripting (XSS)

*
  • M
Authentication Bypass

*
  • M
Authentication Bypass

*
  • L
Authorization Bypass Through User-Controlled Key

*