Vulnerabilidades en SUSE

229 resultados
Análisis Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2024-52281HIGHStored Cross-site Scripting vulnerability in Rancher UIEPSS 0.5%CVE-2026-44941HIGHlibzypp path traversal via "keyhint" in repomd.xmlEPSS 0.5%CVE-2026-41053HIGHOver-inclusive team membership expansion in GitHub App authentication provider for RancherEPSS 0.5%CVE-2024-58259HIGHRancher affected by unauthenticated Denial of ServiceEPSS 0.5%CVE-2025-62877CRITICALHarvest may expose OS default ssh login password via SUSE Virtualization Interactive InstallerEPSS 0.5%CVE-2020-8019HIGHsyslog-ng: Local privilege escalation from new to root in %postEPSS 0.5%CVE-2019-3691HIGHLocal privilege escalation from user munge to rootEPSS 0.5%CVE-2018-19639MEDIUMCode execution if run with command line switch -vEPSS 0.5%CVE-2019-3692HIGHLocal privilege escalation from user news to root in the packaging of innEPSS 0.5%CVE-2026-44942MEDIUMlibzypp .repo files can have an optional path which can lead to path traversal attacksEPSS 0.5%CVE-2026-44932HIGHindirect remote shell command injection via unsanitized DHCP options in wickedEPSS 0.5%CVE-2026-44935CRITICALRancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm DeployerEPSS 0.5%CVE-2026-25705HIGHRancher Extensions have arbitrary file access via path traversalEPSS 0.5%CVE-2019-18898HIGHtrousers: Local privilege escalation from tss to rootEPSS 0.5%CVE-2026-25706HIGHyast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)EPSS 0.5%CVE-2023-32188CRITICALJWT token compromise can allow malicious actions including Remote Code Execution (RCE)EPSS 0.5%CVE-2020-8025MEDIUMoutdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issuesEPSS 0.5%CVE-2024-52280HIGHUsers can issue watch commands for arbitrary resourcesEPSS 0.5%CVE-2019-3695HIGHpcp: Local privilege escalation from user pcp to rootEPSS 0.5%CVE-2022-21953HIGHAuthenticated user can gain unauthorized shell pod and kubectl access in the local cluster EPSS 0.5%