Vulnerabilidades en SUSE

229 resultados
Análisis Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2026-71404HIGHRancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRoleEPSS 0.4%CVE-2026-44937HIGHSUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL ComponentsEPSS 0.4%CVE-2019-3690MEDIUMchkstat follows untrusted symbolic linksEPSS 0.4%CVE-2026-41052CRITICALRancher Privilege Escalation from Project Owner to HostEPSS 0.4%CVE-2024-22030HIGHRancher agents can be hijacked by taking over the Rancher Server URLEPSS 0.4%CVE-2023-32194HIGHRancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'EPSS 0.4%CVE-2022-43754LOWSUMA/UYUNI reflected cross site scripting in /rhn/audit/scap/Search.doEPSS 0.4%CVE-2020-8023HIGHLocal privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2EPSS 0.4%CVE-2026-59679CRITICALfs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2EPSS 0.4%CVE-2020-8028CRITICALsalt-api is accessible to every user on SUSE Manager ServerEPSS 0.4%CVE-2018-19638LOWUser can overwrite arbitrary log files in support tarEPSS 0.4%CVE-2026-44949HIGHUnauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhookEPSS 0.4%CVE-2026-25703HIGHPotential information leakage from manager /network/graph API in NeuVectorEPSS 0.4%CVE-2026-44947MEDIUMStale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in RancherEPSS 0.4%CVE-2022-21951MEDIUMRancher: Weave CNI password is not set if RKE template is used with CNI value overriddenEPSS 0.4%CVE-2026-44946CRITICALSAML Authentication Replay in RancherEPSS 0.4%CVE-2019-18897HIGHLocal privilege escalation from user salt to rootEPSS 0.4%CVE-2019-18901MEDIUMmysql-systemd-helper allows setting 640 permissions of arbitrary filesEPSS 0.4%CVE-2021-25314HIGHhawk: Insecure file permissionsEPSS 0.4%CVE-2024-22032HIGHRancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpecEPSS 0.4%