Known vulnerabilities in grafana-debuginfo
Vendor:
SUSE
Software:
grafana-debuginfo
Software CPE:
cpe:2.3:o:suse:grafana-debuginfo:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
101
Public exploits:
9
Known exploited (KEV):
2
Highest CVSSv4 Score:
9.4
Breakdown by Severity Chart
12.4.5-150200.3.91.1
12.4.5-160002.1.1
12.4.5-150000.1.98.1
12.4.5-150002.4.24.1
11.6.14+security04-160002.1.1
11.6.14+security04-150002.4.21.1
11.6.14+security01-150200.3.88.1
11.6.14+security01-150000.1.95.2
11.6.14+security01-150002.4.14.1
11.6.14+security01-160002.1.1
11.6.11-159000.2.3.2
11.6.11-150200.3.83.1
11.6.11-150000.1.90.1
11.5.10-150002.4.9.1
11.5.10-120002.4.9.1
11.5.10-150200.3.80.1
11.5.10-150002.4.6.1
11.5.10-120002.4.6.1
11.5.7-150002.4.3.3
11.5.7-120002.4.3.2
11.5.5-150200.3.72.2
11.5.5-150000.1.79.1
10.4.15-150200.3.67.1
10.4.15-150200.3.69.1
10.4.15-150000.1.75.1
10.4.15-150000.1.71.1
10.4.15-150200.3.64.1
10.4.13-150200.3.59.1
10.4.13-150000.1.66.1
9.5.18-159000.4.33.4
9.5.18-150200.3.56.1
9.5.18-150000.1.63.2
9.5.16-159000.4.30.2
9.5.8-150000.1.60.2
9.5.8-159000.4.24.1
9.5.5-150000.1.54.3
9.5.5-150200.3.47.1
9.5.5-150000.1.51.1
9.5.5-150200.3.44.1
9.5.1-150200.3.41.3
9.5.1-150000.1.48.5
8.5.22-150000.1.45.1
8.5.22-150200.3.38.1
8.5.20-150000.1.42.1
8.5.20-150200.3.35.1
8.3.5-150000.1.30.1
8.5.15-150200.3.32.1
8.5.15-150000.1.39.1
8.3.10-150000.1.33.1
8.3.10-150200.3.26.1
8.5.13-150100.3.12.1
6.7.4-3.29.1
6.7.4-4.23.1
Vulnerabilities (101)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128147 - Resource exhaustion CVE-2026-31958 |
CWE-400 | Medium | 11.6.14+security01-160002.1.1 | 27.04.2026 |
SB20260427102 SB20260427109 SB20260427110 and 40 more |
||
| #VU124876 - Inefficient Regular Expression Complexity CVE-2026-25547 |
CWE-1333 | Low | 11.6.11-150000.1.90.1, 11.6.11-159000.2.3.2 | 06.04.2026 |
SB2026040628 SB2026040631 SB2026040632 and 13 more |
||
| #VU123311 - Improper Control of Generation of Code ('Code Injection') CVE-2026-1615 |
CWE-94 | High | 11.6.11-150000.1.90.1, 11.6.11-159000.2.3.2 | 27.02.2026 |
SB2026022707 SB2026022708 SB2026032720 and 4 more |
||
| #VU123310 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-61140 |
CWE-1321 | High | 11.6.11-150000.1.90.1, 11.6.11-159000.2.3.2 | 27.02.2026 |
SB2026022706 SB2026022708 SB2026030405 and 3 more |
||
| #VU123174 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-27606 |
CWE-22 | High | 11.6.11-150000.1.90.1, 11.6.11-159000.2.3.2 | 24.02.2026 |
SB2026022445 SB2026040631 SB2026040632 and 4 more |
||
| #VU122756 - Improper Access Control CVE-2026-21722 |
CWE-284 | Low | 11.6.11-150000.1.90.1, 11.6.11-150200.3.83.1, 11.6.11-159000.2.3.2 | 12.02.2026 |
SB2026021238 SB20260325198 SB2026040631 and 1 more |
||
| #VU122160 - Resource Management Errors CVE-2026-21720 |
CWE-399 | Medium | 11.6.11-150000.1.90.1, 11.6.11-150200.3.83.1 | 30.01.2026 |
SB2026013061 SB20260325198 SB2026040631 |
||
| #VU122159 - Improper Privilege Management CVE-2026-21721 |
CWE-269 | Low | 11.6.11-150000.1.90.1, 11.6.11-150200.3.83.1 | 30.01.2026 |
SB2026013061 SB2026022335 SB2026030249 and 4 more |
||
| #VU121928 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2025-13465 |
CWE-1321 | Medium | 11.6.11-150000.1.90.1 | 22.01.2026 |
SB2026012209 SB2026012701 SB2026012744 and 71 more |
||
| #VU120232 - Uncontrolled Recursion CVE-2025-68156 |
CWE-674 | Medium | 11.5.10-120002.4.9.1, 11.5.10-150002.4.9.1, 11.6.11-150000.1.90.1, 11.6.11-150200.3.83.1 | 22.12.2025 |
SB2025122249 SB2025122250 SB2025122251 and 12 more |
||
| #VU120229 - Improper Authentication CVE-2025-62349 |
CWE-287 | Low | 11.6.11-159000.2.3.2 | 19.12.2025 |
SB2025121950 SB2025121951 SB2025121952 and 32 more |
||
| #VU120228 - Improper Control of Generation of Code ('Code Injection') CVE-2025-62348 |
CWE-94 | Medium | 11.6.11-159000.2.3.2 | 19.12.2025 |
SB2025121950 SB2025121951 SB2025121952 and 32 more |
||
| #VU119885 - Improper Neutralization of HTTP Headers for Scripting Syntax CVE-2025-67724 |
CWE-644 | Low | 11.6.11-159000.2.3.2 | 12.12.2025 |
SB2025121205 SB2026010587 SB2026010938 and 35 more |
||
| #VU119884 - Excessive Iteration CVE-2025-67725 |
CWE-834 | Low | 11.6.11-159000.2.3.2 | 12.12.2025 |
SB2025121205 SB2026010587 SB2026010938 and 41 more |
||
| #VU119883 - Excessive Iteration CVE-2025-67726 |
CWE-834 | Medium | 11.6.11-159000.2.3.2 | 12.12.2025 |
SB2025121205 SB2025123045 SB2026010587 and 41 more |
||
| #VU119131 - Interpretation Conflict CVE-2025-12816 |
CWE-436 | Medium | 11.5.10-120002.4.9.1, 11.5.10-150002.4.9.1, 11.6.11-150000.1.90.1 | 04.12.2025 |
SB2025120419 SB2025122219 SB20260116128 and 19 more |
||
| #VU118722 - Allocation of Resources Without Limits or Throttling CVE-2025-47908 |
CWE-770 | Medium | 11.5.7-120002.4.3.2, 11.5.7-150002.4.3.3 | 24.11.2025 |
SB2025112452 SB2025112453 SB2025112454 and 2 more |
||
| #VU113081 - Exposure of sensitive information to an unauthorized actor CVE-2025-3415 |
CWE-200 | Medium | 11.5.7-120002.4.3.2, 11.5.7-150002.4.3.3, 11.6.11-150000.1.90.1, 11.6.11-150200.3.83.1, 11.6.11-159000.2.3.2 | 21.07.2025 |
SB2025072113 SB2025112453 SB2025112454 and 3 more |
||
| #VU113080 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2025-6197 |
CWE-601 | Low | 11.5.7-120002.4.3.2, 11.5.7-150002.4.3.3 | 21.07.2025 |
SB2025072114 SB2025112453 SB2025112454 |
||
| #VU113079 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2025-6023 |
CWE-601 | Medium | 11.5.7-120002.4.3.2, 11.5.7-150002.4.3.3 | 21.07.2025 |
SB2025072114 SB2025112453 SB2025112454 |
Showing elements 1 - 20 out of 101