Vulnerabilities in suse
228 resultsVexday analysis
A SUSE apresenta footprint mínimo na base Vexday com apenas 1 CVE registrado, sem incidentes de exploração ativa (KEV) ou vulnerabilidades críticas documentadas. O risco atual é baixo, sem novos registros nos últimos 90 dias, embora a fraqueza CWE-61 (improper link resolution) mereça atenção em futuros desenvolvimentos.
CVE-2025-54468MEDIUMRancher sends sensitive information to external services through the `/meta/proxy` endpointEPSS 0.4%CVE-2026-44932HIGHindirect remote shell command injection via unsanitized DHCP options in wickedEPSS 0.4%CVE-2024-52283MEDIUMMissing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a certain projectEPSS 0.4%CVE-2023-32192HIGHRancher API Server Cross-site Scripting VulnerabilityEPSS 0.4%CVE-2026-44936MEDIUMRancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yamlEPSS 0.3%CVE-2025-23392MEDIUMReflected XSS in SystemsController.java in spacewalk-javaEPSS 0.3%CVE-2018-17956LOWPassword exposed in process listingEPSS 0.3%CVE-2025-62879MEDIUMRancher Backup Operator pod's logs leak S3 tokensEPSS 0.3%CVE-2025-23393MEDIUMReflected XSS in spacewalk-javaEPSS 0.3%CVE-2019-3688MEDIUMsquid: /usr/sbin/pinger packaged with wrong permissionEPSS 0.3%CVE-2017-9271MEDIUMproxy credentials written to log files by zypperEPSS 0.3%CVE-2024-49504HIGHgrub2 allows bypassing TPM-bound disk encryption on SL(E)M encrypted ImagesEPSS 0.3%CVE-2021-31998MEDIUMinn: %post calls user owned file allowing local privilege escalation to rootEPSS 0.3%CVE-2018-17954CRITICALcrowbar provision leaks admin password to all nodes in cleartextEPSS 0.3%CVE-2018-19636HIGHLocal root exploit via inclusion of attacker controlled shell scriptEPSS 0.3%CVE-2020-8013LOWpermissions: chkstat sets unintended setuid/capabilities for mrsh and wodimEPSS 0.3%CVE-2021-25316LOWLocal DoS of VM live migration due to use of static tmp files in detach_disks.sh in s390-toolsEPSS 0.3%CVE-2019-3682HIGHInsecure API port exposed to all Master Node guest containersEPSS 0.3%CVE-2018-17955LOWStatic tempfile name allows overwriting of arbitrary filesEPSS 0.3%CVE-2021-32001MEDIUMK3s/RKE2 bootstrap data is encrypted with empty string if user does not supply a tokenEPSS 0.3%