Known vulnerabilities in golang-github-prometheus-prometheus - page 2
Vendor:
SUSE
Software:
golang-github-prometheus-prometheus
Software CPE:
cpe:2.3:o:suse:golang-github-prometheus-prometheus:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
94
Public exploits:
8
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.5.4-160002.1.1
3.5.4-150100.4.37.2
3.5.4-150000.3.75.1
3.5.4-150002.3.16.1
3.5.3-160002.1.1
3.5.3-150002.3.13.1
3.5.3-150100.4.34.1
3.5.3-150000.3.72.2
3.5.0-150002.3.8.1
3.5.0-160002.1.1
3.5.0-159000.4.3.2
3.5.0-150000.3.67.1
3.5.0-150002.3.3.1
3.5.0-120002.3.3.1
2.53.4-150100.4.26.2
2.53.4-150000.3.62.2
2.53.4-1.60.2
2.53.3-150100.4.23.1
2.53.3-150000.3.59.1
2.53.3-1.56.1
2.45.6-150100.4.20.1
2.45.6-150000.3.56.1
2.45.6-1.53.1
2.37.6-150100.4.17.1
2.45.0-1.50.2
2.45.0-150000.3.53.1
2.45.0-4.33.3
2.45.0-159000.6.33.1
2.45.0-1.47.3
2.45.0-150000.3.50.3
2.37.6-150000.3.47.2
2.37.6-1.44.3
2.32.1-150100.4.14.1
2.32.1-150000.3.44.1
2.32.1-1.41.1
2.32.1-150100.4.12.1
2.32.1-159000.6.30.4
2.32.1-4.30.1
2.32.1-150100.4.9.2
2.32.1-150000.3.41.2
2.32.1-1.38.1
2.27.1-6.21.2
2.27.1-4.21.1
2.27.1-3.31.1
2.27.1-1.29.2
2.27.1-3.8.1
Vulnerabilities (94)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU120232 - Uncontrolled Recursion CVE-2025-68156 |
CWE-674 | Medium | 3.5.0-120002.3.3.1, 3.5.0-150000.3.67.1, 3.5.0-150002.3.3.1 | 22.12.2025 |
SB2025122249 SB2025122250 SB2025122251 and 12 more |
||
| #VU106253 - Improper input validation CVE-2025-22870 |
CWE-20 | Medium | 2.53.4-150100.4.26.2 | 30.03.2025 |
SB2025033001 SB2025033002 SB2025033003 and 106 more |
||
| #VU104016 - Exposure of sensitive information to an unauthorized actor CVE-2024-22037 |
CWE-200 | Low | 2.53.3-1.56.1, 2.53.3-150000.3.59.1 | 17.02.2025 |
SB2025021737 SB2025021738 SB2025021739 and 5 more |
||
| #VU101894 - Insufficient Technical Documentation CVE-2024-51744 |
CWE-1059 | Low | 2.53.3-1.56.1, 2.53.3-150000.3.59.1, 2.53.3-150100.4.23.1 | 23.12.2024 |
SB2024122304 SB2024122309 SB20241230139 and 21 more |
||
| #VU101777 - Improper Authorization CVE-2024-45337 |
CWE-285 | Medium | 2.53.3-1.56.1, 2.53.3-150000.3.59.1 | 13.12.2024 |
SB2024121332 SB2024121333 SB2024121334 and 93 more |
||
| #VU99259 - Improper Access Control CVE-2024-8118 |
CWE-284 | Low | 2.53.3-1.56.1, 2.53.3-150000.3.59.1 | 22.10.2024 |
SB20241022375 SB2025021467 SB2025021742 and 1 more |
||
| #VU96048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-6837 |
CWE-79 | Medium | 2.53.3-1.56.1, 2.53.3-150000.3.59.1 | 15.08.2024 |
SB2024081534 SB2025021467 SB2025021742 and 1 more |
||
| #VU94616 - Information Exposure Through Log Files CVE-2024-6104 |
CWE-532 | Low | 2.45.6-1.53.1, 2.45.6-150000.3.56.1, 2.45.6-150100.4.20.1 | 19.07.2024 |
SB2024071927 SB2024071929 SB2024071930 and 83 more |
||
| #VU89210 - Incorrect Authorization CVE-2023-6152 |
CWE-863 | Low | 2.53.3-1.56.1, 2.53.3-150000.3.59.1 | 07.05.2024 |
SB2024050715 SB2024050717 SB2024050718 and 8 more |
||
| #VU88184 - Resource exhaustion CVE-2023-45288 |
CWE-400 | Medium | 2.53.4-150100.4.26.2 | 05.04.2024 |
SB2024040533 SB2024040549 SB2024040551 and 189 more |
||
| #VU83546 - Resource exhaustion CVE-2023-45142 |
CWE-400 | Medium | 2.45.6-1.53.1, 2.45.6-150000.3.56.1, 2.45.6-150100.4.20.1 | 29.11.2023 |
SB2023112912 SB2023112913 SB2023112949 and 54 more |
||
| #VU79967 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-40577 |
CWE-79 | Low | 2.45.0-1.50.2, 2.45.0-4.33.3 | 25.08.2023 |
SB2023082505 SB2024012403 SB2024021614 and 5 more |
||
| #VU77652 - Improper Authentication CVE-2023-3128 |
CWE-287 | High | 2.45.0-4.33.3, 2.45.0-159000.6.33.1, 2.53.3-1.56.1, 2.53.3-150000.3.59.1 | 22.06.2023 |
SB2023062281 SB2023071336 SB20230720114 and 15 more |
||
| #VU72686 - Resource exhaustion CVE-2022-41723 |
CWE-400 | Medium | 2.37.6-150100.4.17.1, 2.45.0-1.47.3, 2.45.0-4.33.3, 2.45.0-150000.3.50.3, 2.45.0-159000.6.33.1, 2.45.6-150100.4.20.1 | 01.03.2023 |
SB2023030130 SB2023030131 SB2023030946 and 190 more |
||
| #VU69691 - Use of Password Hash Instead of Password for Authentication CVE-2022-46146 |
CWE-836 | Low | 2.32.1-1.41.1, 2.32.1-150000.3.44.1, 2.32.1-150100.4.12.1, 2.37.6-1.44.3, 2.37.6-150000.3.47.2, 2.37.6-150100.4.17.1, 2.45.0-1.47.3, 2.45.0-4.33.3, 2.45.0-150000.3.50.3, 2.45.0-159000.6.33.1 | 29.11.2022 |
SB2022112926 SB2022113012 SB2023022044 and 33 more |
||
| #VU68390 - Resource exhaustion CVE-2022-41715 |
CWE-400 | Medium | 2.37.6-1.44.3, 2.37.6-150000.3.47.2, 2.37.6-150100.4.17.1, 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1, 2.45.6-150100.4.20.1 | 18.10.2022 |
SB2022101833 SB2022101834 SB2022102005 and 113 more |
||
| #VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-43815 |
CWE-22 | Low | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 15.06.2022 |
SB2021121022 SB2022062026 SB2022102094 and 8 more |
||
| #VU62361 - Improper Control of Generation of Code ('Code Injection') CVE-2021-43138 |
CWE-94 | Medium | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 15.04.2022 |
SB2022041532 SB2022041533 SB2022062103 and 33 more |
||
| #VU61669 - Exposure of sensitive information to an unauthorized actor CVE-2022-0155 |
CWE-200 | Low | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 28.03.2022 |
SB2022032840 SB2022032843 SB2022071505 and 32 more |
||
| #VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-43798 |
CWE-22 | High | 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 | 08.12.2021 |
SB2021120803 SB2022062026 SB2022102094 and 7 more |
Showing elements 21 - 40 out of 94