Known vulnerabilities in prometheus-blackbox_exporter - page 3

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:prometheus-blackbox_exporter:*:*:*:*:*:suse_linux:*:*
Total vulnerabilities: 77
Public exploits: 5
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting prometheus-blackbox_exporter prometheus-blackbox_exporter is affected by 77 known vulnerabilities: 9 high, 35 medium, 33 low Critical High Medium Low

Vulnerabilities (77)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU72128 - Improper Verification of Cryptographic Signature
CVE-2022-31123
CWE-347 Medium
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 11.02.2023 SB2023021201
SB2023021202
SB2023021203
and 15 more
#VU67396 - Improper input validation
CVE-2022-27664
CWE-20 Medium
No
No
0.19.0-1.17.1, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 15.09.2022 SB2022091520
SB2022091521
SB2022092144
and 127 more
#VU65354 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-31097
CWE-79 Low
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 15.07.2022 SB2022071510
SB2022102094
SB2022102641
and 16 more
#VU65353 - Improper Authentication
CVE-2022-31107
CWE-287 High
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 15.07.2022 SB2022071510
SB2022072642
SB2022072643
and 21 more
#VU64430 - Incorrect Authorization
CVE-2021-41244
CWE-863 Medium
No
No
0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 16.06.2022 SB2021111513
SB2022062026
SB2022102094
and 5 more
#VU64404 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43815
CWE-22 Low
No
No
0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 15.06.2022 SB2021121022
SB2022062026
SB2022102094
and 8 more
#VU64402 - Exposure of sensitive information to an unauthorized actor
CVE-2022-21673
CWE-200 Low
No
No
0.19.0-1.8.2, 0.24.0-3.6.3 15.06.2022 SB2022061623
SB2022062026
SB2022081215
and 12 more
#VU64397 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-21702
CWE-79 Low
No
No
0.19.0-1.8.2, 0.24.0-3.6.3 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 14 more
#VU64394 - Authorization Bypass Through User-Controlled Key
CVE-2022-21713
CWE-639 Low
No
No
0.19.0-1.8.2, 0.24.0-3.6.3 15.06.2022 SB2022061621
SB2022062026
SB2022102094
and 13 more
#VU64273 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43813
CWE-22 Low
No
No
0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 14.06.2022 SB2022061422
SB2022062026
SB2022081215
and 16 more
#VU64034 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-3918
CWE-94 High
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 07.06.2022 SB2021111302
SB2022060836
SB2022071504
and 45 more
#VU63461 - Improper input validation
CVE-2022-29170
CWE-20 Low
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 19.05.2022 SB2022051916
SB2024012352
SB2024012403
and 3 more
#VU62361 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-43138
CWE-94 Medium
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 15.04.2022 SB2022041532
SB2022041533
SB2022062103
and 33 more
#VU62039 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2022-27191
CWE-327 Medium
No
No
0.19.0-1.17.1, 0.24.0-3.6.3 10.04.2022 SB2022041004
SB2022041406
SB2022081226
and 91 more
#VU61669 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0155
CWE-200 Low
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 28.03.2022 SB2022032840
SB2022032843
SB2022071505
and 32 more
#VU61599 - Improper input validation
CVE-2022-21698
CWE-20 Medium
No
No
0.19.0-1.8.2, 0.24.0-3.6.3 24.03.2022 SB2022021530
SB2022032413
SB2022040807
and 110 more
#VU58647 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-43798
CWE-22 High
Available
Exploited
0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 08.12.2021 SB2021120803
SB2022062026
SB2022102094
and 7 more
#VU57967 - Improper input validation
CVE-2021-3807
CWE-20 Medium
No
No
0.24.0-3.6.3, 0.24.0-159000.3.6.1 05.11.2021 SB2021110513
SB2021112603
SB2022042257
and 51 more
#VU57926 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41174
CWE-79 Low
Available
No
0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 03.11.2021 SB2021110312
SB2021110517
SB2022062026
and 4 more
#VU56063 - Memory corruption
CVE-2021-3711
CWE-119 High
No
No
0.19.0-1.8.2, 0.24.0-3.6.3, 0.24.0-159000.3.6.1 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 53 more


Showing elements 41 - 60 out of 77