Vulnerabilidades en SUSE

229 resultados
Análisis Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2025-23389HIGHRancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First LoginEPSS 0.5%CVE-2023-32193HIGHNorman API Cross-site Scripting VulnerabilityEPSS 0.5%CVE-2023-22645HIGHkubewarden: Excessive permissions for kubewarden-controller-manager-cluster-roleEPSS 0.5%CVE-2024-58260HIGHRancher update on users can deny the service to the adminEPSS 0.5%CVE-2019-3696HIGHpcp: Local privilege escalation from user pcp to root through migrate_tempdirsEPSS 0.5%CVE-2025-23391CRITICALRancher: Restricted Administrator can change Administrator's passwordsEPSS 0.5%CVE-2018-19637LOWStatic temporary filename allows overwriting of filesEPSS 0.5%CVE-2023-22644CRITICALJWT token compromise can allow malicious actions including Remote Code Execution (RCE)EPSS 0.5%CVE-2023-22648HIGHA Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while theyEPSS 0.5%CVE-2021-36780HIGHUnauthorized data access from replicas through vulnerable instance manager podsEPSS 0.5%CVE-2024-52282MEDIUMRancher Helm Applications may have sensitive values leakedEPSS 0.4%CVE-2017-14806LOWInsecure handling of repodata and packages in SUSE Studio onliteEPSS 0.4%CVE-2026-44950CRITICALfs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2EPSS 0.4%CVE-2026-44938HIGHFleet has PSS Bypass through addLabelsFromOptions in Fleet AgentEPSS 0.4%CVE-2026-41050CRITICALHelm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template renderingEPSS 0.4%CVE-2021-25321HIGHarpwatch: Local privilege escalation from runtime user to rootEPSS 0.4%CVE-2025-54469CRITICALNeuVector Enforcer is vulnerable to Command Injection and Buffer overflowEPSS 0.4%CVE-2022-45157HIGHExposure of vSphere's CPI and CSI credentials in RancherEPSS 0.4%CVE-2026-44948MEDIUMPath Traversal in Rancher Fleet ImageScan GitRepo Path HandlerEPSS 0.4%CVE-2018-20105MEDIUMyast2-rmt exposes CA private key passhrase in log-fileEPSS 0.4%