Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2026-44903
Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy we…
Prometheus
3.5.3 / 3.11.3+
HIGH 7.5
CVE-2026-42154
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) …
Prometheus
3.5.3 / 3.11.3+
HIGH 7.5
CVE-2026-42151
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD …
Prometheus
3.5.3 / 3.11.3+
MEDIUM 6.1
CVE-2026-40179
Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site s…
Prometheus
3.5.2 / 3.11.2+
MEDIUM 5.4
CVE-2023-40577
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on th…
Alertmanager
Mitigation only
HIGH 7.5
CVE-2023-26735
blackbox_exporter v0.23.0 was discovered to contain an access control issue in its probe interface. This vulnerability allows attackers to detect int…
Blackbox Exporter
Mitigation only
HIGH 8.8
CVE-2022-46146
Prometheus Exporter Toolkit is a utility package to build exporters. Prior to versions 0.7.2 and 0.8.2, if someone has access to a Prometheus web.yml…
Exporter Toolkit
0.7.2 / 0.8.2+
HIGH 7.5
CVE-2022-21698EPSS 6%
client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTT…
Client Golang
1.11.1+
MEDIUM 6.1
CVE-2021-29622EPSS 20%
Prometheus is an open-source monitoring system and time series database. In 2.23.0, Prometheus changed its default UI to the New ui. To ensure a seam…
Prometheus
2.26.1+
MEDIUM 5.8
CVE-2020-16248
Prometheus Blackbox Exporter through 0.17.0 allows /probe?target= SSRF. NOTE: follow-on discussion suggests that this might plausibly be interpreted …
Blackbox Exporter
after 0.17.0
MEDIUM 6.1
CVE-2019-3826
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an au…
Prometheus
2.7.1+