Known vulnerabilities in firewalld-prometheus-config - page 2
Vendor:
SUSE
Software:
firewalld-prometheus-config
Software CPE:
cpe:2.3:o:suse:firewalld-prometheus-config:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
76
Public exploits:
7
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.1-150000.3.75.1
0.1-150002.3.16.1
0.1-150002.3.13.1
0.1-150000.3.72.2
0.1-150002.3.8.1
0.1-159000.4.3.2
0.1-150000.3.67.1
0.1-150002.3.3.1
0.1-150100.4.26.2
0.1-150000.3.62.2
0.1-150100.4.23.1
0.1-150000.3.59.1
0.1-150100.4.20.1
0.1-150000.3.56.1
0.1-150100.4.17.1
0.1-150000.3.53.1
0.1-159000.6.33.1
0.1-150000.3.50.3
0.1-150000.3.47.2
0.1-150100.4.14.1
0.1-150000.3.44.1
0.1-150100.4.12.1
0.1-159000.6.30.4
0.1-150100.4.9.2
0.1-150000.3.41.2
Vulnerabilities (76)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU104016 - Exposure of sensitive information to an unauthorized actor CVE-2024-22037 |
CWE-200 | Low | 0.1-150000.3.59.1 | 17.02.2025 |
SB2025021737 SB2025021738 SB2025021739 and 5 more |
||
| #VU101894 - Insufficient Technical Documentation CVE-2024-51744 |
CWE-1059 | Low | 0.1-150000.3.59.1, 0.1-150100.4.23.1 | 23.12.2024 |
SB2024122304 SB2024122309 SB20241230139 and 21 more |
||
| #VU101777 - Improper Authorization CVE-2024-45337 |
CWE-285 | Medium | 0.1-150000.3.59.1 | 13.12.2024 |
SB2024121332 SB2024121333 SB2024121334 and 93 more |
||
| #VU96048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-6837 |
CWE-79 | Medium | 0.1-150000.3.59.1 | 15.08.2024 |
SB2024081534 SB2025021467 SB2025021742 and 1 more |
||
| #VU94616 - Information Exposure Through Log Files CVE-2024-6104 |
CWE-532 | Low | 0.1-150000.3.56.1, 0.1-150100.4.20.1 | 19.07.2024 |
SB2024071927 SB2024071929 SB2024071930 and 83 more |
||
| #VU89210 - Incorrect Authorization CVE-2023-6152 |
CWE-863 | Low | 0.1-150000.3.59.1 | 07.05.2024 |
SB2024050715 SB2024050717 SB2024050718 and 8 more |
||
| #VU83546 - Resource exhaustion CVE-2023-45142 |
CWE-400 | Medium | 0.1-150000.3.56.1, 0.1-150100.4.20.1 | 29.11.2023 |
SB2023112912 SB2023112913 SB2023112949 and 54 more |
||
| #VU72686 - Resource exhaustion CVE-2022-41723 |
CWE-400 | Medium | 0.1-150000.3.50.3, 0.1-150100.4.17.1, 0.1-150100.4.20.1, 0.1-159000.6.33.1 | 01.03.2023 |
SB2023030130 SB2023030131 SB2023030946 and 190 more |
||
| #VU72128 - Improper Verification of Cryptographic Signature CVE-2022-31123 |
CWE-347 | Medium | 0.1-159000.6.33.1 | 11.02.2023 |
SB2023021201 SB2023021202 SB2023021203 and 15 more |
||
| #VU69691 - Use of Password Hash Instead of Password for Authentication CVE-2022-46146 |
CWE-836 | Low | 0.1-150000.3.44.1, 0.1-150000.3.47.2, 0.1-150000.3.50.3, 0.1-150100.4.12.1, 0.1-150100.4.17.1, 0.1-159000.6.33.1 | 29.11.2022 |
SB2022112926 SB2022113012 SB2023022044 and 33 more |
||
| #VU68390 - Resource exhaustion CVE-2022-41715 |
CWE-400 | Medium | 0.1-150000.3.47.2, 0.1-150000.3.53.1, 0.1-150100.4.17.1, 0.1-150100.4.20.1, 0.1-159000.6.33.1 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 113 more |
||
| #VU65355 - Incorrect Regular Expression CVE-2020-7753 |
CWE-185 | Medium | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 15.07.2022 |
SB2020102724 SB2022071510 SB2023062230 and 12 more |
||
| #VU65353 - Improper Authentication CVE-2022-31107 |
CWE-287 | High | 0.1-159000.6.33.1 | 15.07.2022 |
SB2022071510 SB2022072642 SB2022072643 and 21 more |
||
| #VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-43815 |
CWE-22 | Low | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 15.06.2022 |
SB2021121022 SB2022062026 SB2022102094 and 8 more |
||
| #VU64273 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-43813 |
CWE-22 | Low | 0.1-159000.6.33.1 | 14.06.2022 |
SB2022061422 SB2022062026 SB2022081215 and 16 more |
||
| #VU64034 - Improper Control of Generation of Code ('Code Injection') CVE-2021-3918 |
CWE-94 | High | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 07.06.2022 |
SB2021111302 SB2022060836 SB2022071504 and 45 more |
||
| #VU62361 - Improper Control of Generation of Code ('Code Injection') CVE-2021-43138 |
CWE-94 | Medium | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 15.04.2022 |
SB2022041532 SB2022041533 SB2022062103 and 33 more |
||
| #VU61669 - Exposure of sensitive information to an unauthorized actor CVE-2022-0155 |
CWE-200 | Low | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 28.03.2022 |
SB2022032840 SB2022032843 SB2022071505 and 32 more |
||
| #VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-43798 |
CWE-22 | High | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 08.12.2021 |
SB2021120803 SB2022062026 SB2022102094 and 7 more |
||
| #VU57967 - Improper input validation CVE-2021-3807 |
CWE-20 | Medium | 0.1-150000.3.53.1, 0.1-159000.6.33.1 | 05.11.2021 |
SB2021110513 SB2021112603 SB2022042257 and 51 more |
Showing elements 21 - 40 out of 76