Known vulnerabilities in golang-github-prometheus-prometheus - page 2

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:golang-github-prometheus-prometheus:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 94
Public exploits: 8
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting golang-github-prometheus-prometheus golang-github-prometheus-prometheus is affected by 94 known vulnerabilities: 10 high, 44 medium, 40 low Critical High Medium Low

Vulnerabilities (94)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU120232 - Uncontrolled Recursion
CVE-2025-68156
CWE-674 Medium
No
No
3.5.0-120002.3.3.1, 3.5.0-150000.3.67.1, 3.5.0-150002.3.3.1 22.12.2025 SB2025122249
SB2025122250
SB2025122251
and 12 more
#VU106253 - Improper input validation
CVE-2025-22870
CWE-20 Medium
Available
No
2.53.4-150100.4.26.2 30.03.2025 SB2025033001
SB2025033002
SB2025033003
and 106 more
#VU104016 - Exposure of sensitive information to an unauthorized actor
CVE-2024-22037
CWE-200 Low
No
No
2.53.3-1.56.1, 2.53.3-150000.3.59.1 17.02.2025 SB2025021737
SB2025021738
SB2025021739
and 5 more
#VU101894 - Insufficient Technical Documentation
CVE-2024-51744
CWE-1059 Low
No
No
2.53.3-1.56.1, 2.53.3-150000.3.59.1, 2.53.3-150100.4.23.1 23.12.2024 SB2024122304
SB2024122309
SB20241230139
and 21 more
#VU101777 - Improper Authorization
CVE-2024-45337
CWE-285 Medium
Available
No
2.53.3-1.56.1, 2.53.3-150000.3.59.1 13.12.2024 SB2024121332
SB2024121333
SB2024121334
and 93 more
#VU99259 - Improper Access Control
CVE-2024-8118
CWE-284 Low
No
No
2.53.3-1.56.1, 2.53.3-150000.3.59.1 22.10.2024 SB20241022375
SB2025021467
SB2025021742
and 1 more
#VU96048 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-6837
CWE-79 Medium
No
No
2.53.3-1.56.1, 2.53.3-150000.3.59.1 15.08.2024 SB2024081534
SB2025021467
SB2025021742
and 1 more
#VU94616 - Information Exposure Through Log Files
CVE-2024-6104
CWE-532 Low
No
No
2.45.6-1.53.1, 2.45.6-150000.3.56.1, 2.45.6-150100.4.20.1 19.07.2024 SB2024071927
SB2024071929
SB2024071930
and 83 more
#VU89210 - Incorrect Authorization
CVE-2023-6152
CWE-863 Low
No
No
2.53.3-1.56.1, 2.53.3-150000.3.59.1 07.05.2024 SB2024050715
SB2024050717
SB2024050718
and 8 more
#VU88184 - Resource exhaustion
CVE-2023-45288
CWE-400 Medium
Available
No
2.53.4-150100.4.26.2 05.04.2024 SB2024040533
SB2024040549
SB2024040551
and 189 more
#VU83546 - Resource exhaustion
CVE-2023-45142
CWE-400 Medium
No
No
2.45.6-1.53.1, 2.45.6-150000.3.56.1, 2.45.6-150100.4.20.1 29.11.2023 SB2023112912
SB2023112913
SB2023112949
and 54 more
#VU79967 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-40577
CWE-79 Low
No
No
2.45.0-1.50.2, 2.45.0-4.33.3 25.08.2023 SB2023082505
SB2024012403
SB2024021614
and 5 more
#VU77652 - Improper Authentication
CVE-2023-3128
CWE-287 High
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1, 2.53.3-1.56.1, 2.53.3-150000.3.59.1 22.06.2023 SB2023062281
SB2023071336
SB20230720114
and 15 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
2.37.6-150100.4.17.1, 2.45.0-1.47.3, 2.45.0-4.33.3, 2.45.0-150000.3.50.3, 2.45.0-159000.6.33.1, 2.45.6-150100.4.20.1 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU69691 - Use of Password Hash Instead of Password for Authentication
CVE-2022-46146
CWE-836 Low
No
No
2.32.1-1.41.1, 2.32.1-150000.3.44.1, 2.32.1-150100.4.12.1, 2.37.6-1.44.3, 2.37.6-150000.3.47.2, 2.37.6-150100.4.17.1, 2.45.0-1.47.3, 2.45.0-4.33.3, 2.45.0-150000.3.50.3, 2.45.0-159000.6.33.1 29.11.2022 SB2022112926
SB2022113012
SB2023022044
and 33 more
#VU68390 - Resource exhaustion
CVE-2022-41715
CWE-400 Medium
No
No
2.37.6-1.44.3, 2.37.6-150000.3.47.2, 2.37.6-150100.4.17.1, 2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1, 2.45.6-150100.4.20.1 18.10.2022 SB2022101833
SB2022101834
SB2022102005
and 113 more
#VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43815
CWE-22 Low
No
No
2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 15.06.2022 SB2021121022
SB2022062026
SB2022102094
and 8 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Available
Exploited
2.45.0-1.50.2, 2.45.0-4.33.3, 2.45.0-150000.3.53.1, 2.45.0-159000.6.33.1 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more


Showing elements 21 - 40 out of 94