Skip to content
Noroxi

Graphite project records

7 published records for vendor graphite project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 14.3%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

7 records
  • CVE-2013-5093
    39Monitor

    The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, whi

    MediumCVSS 6.8WeaponizedEPSS 39%

    graphite project · graphiteSep 27, 2013

  • send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF.

    HighCVSS 7.5Proof of conceptEPSS 15%

    graphite project · graphiteOct 11, 2019

  • CVE-2013-5942
    28Monitor

    Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted

    MediumCVSS 6.8No exploitEPSS 2%

    graphite project · graphiteSep 27, 2013

  • CVE-2022-4728
    21Monitor

    Graphite Web Cookie cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    graphite project · graphiteDec 27, 2022

  • CVE-2022-4730
    21Monitor

    Graphite Web Absolute Time Range cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    graphite project · graphiteDec 27, 2022

  • CVE-2022-4729
    21Monitor

    Graphite Web Template Name cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    graphite project · graphiteDec 27, 2022

  • CVE-2013-5943
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML

    MediumCVSS 4.3No exploitEPSS 2%

    graphite project · graphiteSep 27, 2013