Known vulnerabilities in firewalld-prometheus-config - page 2

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:firewalld-prometheus-config:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 76
Public exploits: 7
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting firewalld-prometheus-config firewalld-prometheus-config is affected by 76 known vulnerabilities: 9 high, 34 medium, 33 low Critical High Medium Low

Vulnerabilities (76)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU104016 - Exposure of sensitive information to an unauthorized actor
CVE-2024-22037
CWE-200 Low
No
No
0.1-150000.3.59.1 17.02.2025 SB2025021737
SB2025021738
SB2025021739
and 5 more
#VU101894 - Insufficient Technical Documentation
CVE-2024-51744
CWE-1059 Low
No
No
0.1-150000.3.59.1, 0.1-150100.4.23.1 23.12.2024 SB2024122304
SB2024122309
SB20241230139
and 21 more
#VU101777 - Improper Authorization
CVE-2024-45337
CWE-285 Medium
Available
No
0.1-150000.3.59.1 13.12.2024 SB2024121332
SB2024121333
SB2024121334
and 93 more
#VU96048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-6837
CWE-79 Medium
No
No
0.1-150000.3.59.1 15.08.2024 SB2024081534
SB2025021467
SB2025021742
and 1 more
#VU94616 - Information Exposure Through Log Files
CVE-2024-6104
CWE-532 Low
No
No
0.1-150000.3.56.1, 0.1-150100.4.20.1 19.07.2024 SB2024071927
SB2024071929
SB2024071930
and 83 more
#VU89210 - Incorrect Authorization
CVE-2023-6152
CWE-863 Low
No
No
0.1-150000.3.59.1 07.05.2024 SB2024050715
SB2024050717
SB2024050718
and 8 more
#VU83546 - Resource exhaustion
CVE-2023-45142
CWE-400 Medium
No
No
0.1-150000.3.56.1, 0.1-150100.4.20.1 29.11.2023 SB2023112912
SB2023112913
SB2023112949
and 54 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
0.1-150000.3.50.3, 0.1-150100.4.17.1, 0.1-150100.4.20.1, 0.1-159000.6.33.1 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU72128 - Improper Verification of Cryptographic Signature
CVE-2022-31123
CWE-347 Medium
No
No
0.1-159000.6.33.1 11.02.2023 SB2023021201
SB2023021202
SB2023021203
and 15 more
#VU69691 - Use of Password Hash Instead of Password for Authentication
CVE-2022-46146
CWE-836 Low
No
No
0.1-150000.3.44.1, 0.1-150000.3.47.2, 0.1-150000.3.50.3, 0.1-150100.4.12.1, 0.1-150100.4.17.1, 0.1-159000.6.33.1 29.11.2022 SB2022112926
SB2022113012
SB2023022044
and 33 more
#VU68390 - Resource exhaustion
CVE-2022-41715
CWE-400 Medium
No
No
0.1-150000.3.47.2, 0.1-150000.3.53.1, 0.1-150100.4.17.1, 0.1-150100.4.20.1, 0.1-159000.6.33.1 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 113 more
#VU65355 - Incorrect Regular Expression
CVE-2020-7753
CWE-185 Medium
No
No
0.1-150000.3.53.1, 0.1-159000.6.33.1 15.07.2022 SB2020102724
SB2022071510
SB2023062230
and 12 more
#VU65353 - Improper Authentication
CVE-2022-31107
CWE-287 High
No
No
0.1-159000.6.33.1 15.07.2022 SB2022071510
SB2022072642
SB2022072643
and 21 more
#VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43815
CWE-22 Low
No
No
0.1-150000.3.53.1, 0.1-159000.6.33.1 15.06.2022 SB2021121022
SB2022062026
SB2022102094
and 8 more
#VU64273 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43813
CWE-22 Low
No
No
0.1-159000.6.33.1 14.06.2022 SB2022061422
SB2022062026
SB2022081215
and 16 more
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
0.1-150000.3.53.1, 0.1-159000.6.33.1 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
0.1-150000.3.53.1, 0.1-159000.6.33.1 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
0.1-150000.3.53.1, 0.1-159000.6.33.1 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Available
Exploited
0.1-150000.3.53.1, 0.1-159000.6.33.1 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more
#VU57967 - Improper input validation
CVE-2021-3807
CWE-20 Medium
No
No
0.1-150000.3.53.1, 0.1-159000.6.33.1 05.11.2021 SB2021110513
SB2021112603
SB2022042257
and 51 more


Showing elements 21 - 40 out of 76