TGViewer
Netlas.io Netlas.io @netlas Β· 2.33K subscribers
Post #246 781
CVE-2024-9264: Execute Arbitrary Code in Grafana, 9.9 rating πŸ”₯πŸ”₯πŸ”₯

Grafana users at Viewer level and above can perform command injection using a vulnerability in SQL Expressions.

More then 104k instances at Netlas.io:
πŸ‘‰ Link: https://nt.ls/oQJHO
πŸ‘‰ Dork: http.favicon.hash_sha256:80a7f87a79169cf0ac1ed3250d7c509368190a97bc7182cd4705deb8f8c70174 AND http.title:"Grafana"

Vendor's advisory: https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/
  • πŸ”₯ 5
  • πŸ‘Ύ 2
  • πŸ‘ 1
More from @netlas
  1. Sep 29, 2026CVE-2026-88771 & CVE-2026-887722: RCE and/or DoS in Citrix NetScaler ADC and NetScaler Gat…
  2. Sep 25, 2026CVE-2026-13016 and others: Multiple vulnerabilities in ServiceNow, up to 9.3 Rating πŸ”₯ Rec…
  3. Sep 24, 2026CVE-2026-88804: Unauthenticated update of public UI settings leading to stored XSS in Ranc…
  4. Sep 23, 2026CVE-2026-87902: Path Traversal in WordPress leading to RCE, 9.2 Rating πŸ”₯ Another newly di…
  5. Sep 22, 2026CVE-2026-93952: Improper Input Validation in VeloCloud Orchestrator, 10.0 Rating πŸ”₯ A rece…
  6. Sep 21, 2026CVE-2026-13684 and others: Multiple vulnerabilities in Synology DSM, up to 9.8 Rating πŸ”₯ S…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’