Known vulnerabilities in grafana-debuginfo - page 5

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:grafana-debuginfo:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 101
Public exploits: 9
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting grafana-debuginfo grafana-debuginfo is affected by 101 known vulnerabilities: 13 high, 42 medium, 46 low Critical High Medium Low

Vulnerabilities (101)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78913 - Improper Certificate Validation
CVE-2023-29409
CWE-295 Medium
No
No
9.5.5-150000.1.54.3, 9.5.5-150200.3.47.1 03.08.2023 SB2023080320
SB2023080321
SB2023080370
and 98 more
#VU78470 - Missing Authorization
CVE-2023-2183
CWE-862 Low
No
No
9.5.5-150000.1.51.1, 9.5.5-150200.3.44.1, 9.5.8-159000.4.24.1 20.07.2023 SB20230720110
SB20230720114
SB20230720115
and 9 more
#VU77623 - Improper Synchronization
CVE-2023-2801
CWE-662 Medium
No
No
9.5.5-150000.1.51.1, 9.5.5-150200.3.44.1, 9.5.8-159000.4.24.1 22.06.2023 SB2023062244
SB20230720114
SB20230720115
and 8 more
#VU77620 - Exposure of sensitive information to an unauthorized actor
CVE-2023-1387
CWE-200 Medium
No
No
9.5.1-150000.1.48.5, 9.5.1-150200.3.41.3, 9.5.8-159000.4.24.1 22.06.2023 SB2023062227
SB2023062230
SB2023062231
and 7 more
#VU75360 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-1410
CWE-79 Low
No
No
8.5.22-150000.1.45.1, 8.5.22-150200.3.38.1, 9.5.1-150000.1.48.5, 9.5.1-150200.3.41.3, 9.5.8-159000.4.24.1 19.04.2023 SB2023041950
SB2023041951
SB2023041952
and 11 more
#VU75359 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-0594
CWE-79 Low
No
No
8.5.22-150000.1.45.1, 8.5.22-150200.3.38.1, 9.5.8-159000.4.24.1 19.04.2023 SB2023041949
SB2023041951
SB2023041952
and 6 more
#VU75358 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-0507
CWE-79 Low
No
No
8.5.22-150000.1.45.1, 8.5.22-150200.3.38.1, 9.5.8-159000.4.24.1 19.04.2023 SB2023041949
SB2023041951
SB2023041952
and 6 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
8.5.20-150000.1.42.1, 8.5.20-150200.3.35.1, 9.5.5-150000.1.54.3, 9.5.8-159000.4.24.1 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU71566 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-39324
CWE-451 Low
No
No
8.5.20-150000.1.42.1, 8.5.20-150200.3.35.1, 9.5.8-159000.4.24.1 26.01.2023 SB2023012631
SB2023032032
SB2023032033
and 12 more
#VU69691 - Use of Password Hash Instead of Password for Authentication
CVE-2022-46146
CWE-836 Low
No
No
8.5.20-150000.1.42.1, 8.5.20-150200.3.35.1, 9.5.1-150000.1.48.5, 9.5.5-150000.1.54.3, 9.5.8-159000.4.24.1 29.11.2022 SB2022112926
SB2022113012
SB2023022044
and 33 more
#VU67588 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-1734
CWE-78 High
No
No
6.7.4-3.29.1, 6.7.4-4.23.1 22.09.2022 SB2022092241
SB2022092242
SB2020041808
and 1 more
#VU64905 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-34265
CWE-89 High
Available
No
6.7.4-3.29.1, 6.7.4-4.23.1 04.07.2022 SB2022070425
SB2022070438
SB2022080147
and 8 more
#VU64402 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21673
CWE-200 Low
No
No
8.3.5-150000.1.30.1, 8.5.13-150100.3.12.1 15.06.2022 SB2022061623
SB2022062026
SB2022081215
and 12 more
#VU64399 - Cross-Site Request Forgery (CSRF)
CVE-2022-21703
CWE-352 Medium
No
No
8.3.5-150000.1.30.1, 8.3.10-150200.3.26.1, 8.5.13-150100.3.12.1 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
8.3.5-150000.1.30.1, 8.3.10-150200.3.26.1, 8.5.13-150100.3.12.1 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU62050 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28346
CWE-89 High
Available
No
6.7.4-3.29.1, 6.7.4-4.23.1 11.04.2022 SB2022041110
SB2022041125
SB2022041126
and 14 more
#VU61798 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24790
CWE-444 Medium
No
No
6.7.4-3.29.1, 6.7.4-4.23.1 01.04.2022 SB2022040112
SB2022052603
SB2022092241
and 12 more
#VU58824 - Improper input validation
CVE-2021-44716
CWE-20 Medium
No
No
6.7.4-4.23.1 10.12.2021 SB2021121010
SB2021121011
SB2021121605
and 67 more
#VU57320 - Improper Access Control
CVE-2021-39226
CWE-284 Medium
Available
Exploited
6.7.4-3.29.1, 6.7.4-4.23.1, 8.3.5-150000.1.30.1 12.10.2021 SB2021101262
SB2021101320
SB2021101321
and 22 more
#VU24218 - Improper input validation
CVE-2019-11287
CWE-20 Medium
No
No
6.7.4-3.29.1, 6.7.4-4.23.1 13.01.2020 SB2019112307
SB2020011311
SB2021062428
and 5 more


Showing elements 81 - 100 out of 101