Vulnerabilidades en SUSE

229 resultados
Análisis Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2024-49503MEDIUMReflected XSS in Setup Wizard, Organization Credentials in spacewalk-webEPSS 0.3%CVE-2019-3687MEDIUM"easy" permission profile allows everyone execute dumpcap and read all network trafficEPSS 0.3%CVE-2025-53883CRITICALspacewalk-java has various XSS issues on search pageEPSS 0.3%CVE-2024-58269MEDIUMRancher exposes sensitive information through audit logsEPSS 0.3%CVE-2025-53880HIGHsusemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversalEPSS 0.3%CVE-2021-25317LOWcups: ownership of /var/log/cups allows the lp user to create files as rootEPSS 0.3%CVE-2026-71401MEDIUMwicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds readEPSS 0.3%CVE-2020-8030LOWskuba: Insecure /tmp usage when joining node to clusterEPSS 0.3%CVE-2025-54471MEDIUMNeuVector is shipping cryptographic material into its binaryEPSS 0.3%CVE-2025-54467MEDIUMNeuVector process with sensitive arguments lead to leakageEPSS 0.3%CVE-2022-31254HIGHrmt-server-pubcloud allows to escalate from user _rmt to rootEPSS 0.2%CVE-2026-71402MEDIUMwicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total lengthEPSS 0.2%CVE-2026-55996MEDIUMUnauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agentEPSS 0.2%CVE-2021-46705MEDIUMgrub2-once uses fixed file name in /var/tmpEPSS 0.2%CVE-2022-31256HIGHsendmail: mail to root privilege escalation via sm-client.pre scriptEPSS 0.2%CVE-2025-46809MEDIUMMulti Linux Manager epxoses the plain text HTTP Proxy user:password in logsEPSS 0.2%CVE-2024-58267HIGHRancher CLI SAML authentication is vulnerable to phishing attacksEPSS 0.2%CVE-2024-52284HIGHRancher Fleet Helm Values are stored inside BundleDeployment in plain textEPSS 0.2%CVE-2025-46802MEDIUMTemporary chown() of users' TTY to mode 0666 allows PTY hijacking in screenEPSS 0.2%CVE-2022-45153HIGHsaphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.slsEPSS 0.2%