Vulnerabilidades en SUSE

229 resultados
Análisis Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2026-44940MEDIUMService token exposure and potential privilege escalation in SUSE ObservabilityEPSS 0.2%CVE-2022-31251MEDIUMslurm: %post for slurm-testsuite operates as root in user owned directoryEPSS 0.2%CVE-2024-22038MEDIUMDoS attacks, information leaks etc. with crafted Git repositories in obs-scm-bridgeEPSS 0.2%CVE-2024-22034MEDIUMCrafted projects can overwrite special files in the .osc config directoryEPSS 0.2%CVE-2025-71261HIGHHarvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSEPSS 0.2%CVE-2023-32199MEDIUMRancher user retains access to clusters despite Global Role removalEPSS 0.2%CVE-2022-45155MEDIUMobs-service-go_modules: arbitrary directory deleteEPSS 0.2%CVE-2020-8017MEDIUMrace condition on texlive-filesystem cron job allows for the deletion of unintended filesEPSS 0.2%CVE-2023-32190HIGHmlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readableEPSS 0.2%CVE-2025-46808MEDIUMSensitive information is leaked into NeuVector’s manager container logsEPSS 0.2%CVE-2026-44933HIGHPath Traversal in Plugin Loading in libzyppEPSS 0.2%CVE-2025-54470HIGHNeuVector telemetry sender is vulnerable to MITM and DoSEPSS 0.2%CVE-2024-22029HIGHtomcat packaging allows for escalation to root from tomcat userEPSS 0.2%CVE-2025-62875MEDIUMLocal DoS in OpenSMTPD via UNIX domain socket smtpd.sockEPSS 0.2%CVE-2025-53884MEDIUMNeuVector has an insecure password storage vulnerable to rainbow attackEPSS 0.2%CVE-2022-45154MEDIUMsupportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.shEPSS 0.2%CVE-2024-22037MEDIUMDatabase password leaked by systemd uyuni-server-attestation serviceEPSS 0.2%CVE-2026-59674HIGHLPE from suricata user to root due to chown in %post in suricata packagingEPSS 0.2%CVE-2026-41054HIGHMissing exit out of permission check in haveged could lead to root exploitEPSS 0.2%CVE-2025-67601HIGHRancher CLI skips TLS verification on Rancher CLI login commandEPSS 0.2%