Skip to content
Noroxi

prometheus records

11 published records for vendor prometheus.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
81.8%
Median publish → KEV
No record has entered KEV

All records

11 records
  • Prometheus Exporter Toolkit vulnerable to basic authentication bypass

    HighCVSS 8.8No exploitEPSS 1%

    prometheus · exporter toolkitNov 29, 2022

  • Uncontrolled Resource Consumption in promhttp

    HighCVSS 7.5No exploitEPSS 6%

    prometheus · client golangFeb 15, 2022

  • Arbitrary redirects under /new endpoint

    MediumCVSS 6.1Proof of conceptEPSS 20%

    prometheus · prometheusMay 19, 2021

  • Prometheus: remote read endpoint allows denial of service via crafted snappy payload

    HighCVSS 7.5Proof of conceptEPSS 1%

    prometheus · prometheusMay 4, 2026

  • blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface.

    HighCVSS 7.5No exploitEPSS 1%

    prometheus · blackbox exporterApr 25, 2023

  • Prometheus Azure AD remote write OAuth client secret exposed via config API

    HighCVSS 7.5No exploitEPSS 0%

    prometheus · prometheusMay 4, 2026

  • CVE-2019-3826
    25Monitor

    A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1.

    MediumCVSS 6.1No exploitEPSS 3%

    prometheus · prometheusMar 26, 2019

  • Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF.

    MediumCVSS 5.8Proof of conceptEPSS 3%

    prometheus · blackbox exporterAug 9, 2020

  • Alertmanager UI is vulnerable to stored XSS via the /api/v1/alerts endpoint

    MediumCVSS 5.4No exploitEPSS 1%

    prometheus · alertmanagerAug 24, 2023

  • Prometheus: Stored XSS via metric names and label values in web UI tooltips and metrics explorer

    MediumCVSS 5.3Proof of conceptEPSS 0%

    prometheus · prometheusApr 15, 2026

  • Prometheus: Stored XSS via crafted histogram bucket label values in the heatmap display of the old Prometheus web UI

    MediumCVSS 5.1No exploitEPSS 0%

    prometheus · prometheusMay 26, 2026