Known vulnerabilities in golang-github-prometheus-prometheus - page 4

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:golang-github-prometheus-prometheus:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 94
Public exploits: 8
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting golang-github-prometheus-prometheus golang-github-prometheus-prometheus is affected by 94 known vulnerabilities: 10 high, 44 medium, 40 low Critical High Medium Low

Vulnerabilities (94)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU71567 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-23552
CWE-79 Low
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 26.01.2023 SB2023012632
SB2023032032
SB2023032033
and 10 more
#VU67396 - Improper input validation
CVE-2022-27664
CWE-20 Medium
No
No
2.37.6-1.44.3, 2.45.0-4.33.3, 2.45.0-159000.6.33.1 15.09.2022 SB2022091520
SB2022091521
SB2022092144
and 127 more
#VU65354 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31097
CWE-79 Low
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 15.07.2022 SB2022071510
SB2022102094
SB2022102641
and 16 more
#VU64430 - Incorrect Authorization
CVE-2021-41244
CWE-863 Medium
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 16.06.2022 SB2021111513
SB2022062026
SB2022102094
and 5 more
#VU64402 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21673
CWE-200 Low
No
No
2.45.0-4.33.3 15.06.2022 SB2022061623
SB2022062026
SB2022081215
and 12 more
#VU64399 - Cross-Site Request Forgery (CSRF)
CVE-2022-21703
CWE-352 Medium
No
No
2.45.0-4.33.3 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
2.45.0-4.33.3 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64394 - Authorization Bypass Through User-Controlled Key
CVE-2022-21713
CWE-639 Low
No
No
2.45.0-4.33.3 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 13 more
#VU64273 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43813
CWE-22 Low
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 14.06.2022 SB2022061422
SB2022062026
SB2022081215
and 16 more
#VU63461 - Improper input validation
CVE-2022-29170
CWE-20 Low
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 19.05.2022 SB2022051916
SB2024012352
SB2024012403
and 3 more
#VU62039 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-27191
CWE-327 Medium
No
No
2.37.6-1.44.3, 2.45.0-4.33.3 10.04.2022 SB2022041004
SB2022041406
SB2022081226
and 91 more
#VU57926 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41174
CWE-79 Low
Available
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 03.11.2021 SB2021110312
SB2021110517
SB2022062026
and 4 more
#VU57422 - Information Exposure Through an Error Message
CVE-2021-3620
CWE-209 Low
No
No
2.45.0-159000.6.33.1 19.10.2021 SB2021101903
SB2021101904
SB2021101905
and 10 more
#VU57320 - Improper Access Control
CVE-2021-39226
CWE-284 Medium
Available
Exploited
2.45.0-4.33.3 12.10.2021 SB2021101262
SB2021101320
SB2021101321
and 22 more
#VU56063 - Memory corruption
CVE-2021-3711
CWE-119 High
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 53 more
#VU55287 - NULL Pointer Dereference
CVE-2021-36222
CWE-476 Medium
No
No
2.45.0-4.33.3, 2.45.0-159000.6.33.1 25.07.2021 SB2021072501
SB2021072502
SB2021080601
and 24 more
#VU54626 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3583
CWE-94 High
No
No
2.45.0-159000.6.33.1 08.07.2021 SB2021070822
SB2021070823
SB2021071517
and 12 more
#VU52984 - Information Exposure Through Log Files
CVE-2021-3447
CWE-532 Low
No
No
2.45.0-159000.6.33.1 10.05.2021 SB2021040180
SB2021051001
SB2021072616
and 13 more
#VU50818 - Information Exposure Through Log Files
CVE-2021-20228
CWE-532 Low
No
No
2.45.0-159000.6.33.1 22.02.2021 SB2021022203
SB2021022205
SB2021022512
and 7 more
#VU50428 - Information Exposure Through Log Files
CVE-2021-20178
CWE-532 Low
No
No
2.45.0-159000.6.33.1 09.02.2021 SB2021020903
SB2021020904
SB2021022512
and 10 more


Showing elements 61 - 80 out of 94