Vulnerabilidades em SUSE

229 resultados
Análise Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2022-31254HIGHrmt-server-pubcloud allows to escalate from user _rmt to rootEPSS 0.2%CVE-2026-71404HIGHRancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRoleEPSS 0.2%CVE-2021-46705MEDIUMgrub2-once uses fixed file name in /var/tmpEPSS 0.2%CVE-2022-31256HIGHsendmail: mail to root privilege escalation via sm-client.pre scriptEPSS 0.2%CVE-2025-46809MEDIUMMulti Linux Manager epxoses the plain text HTTP Proxy user:password in logsEPSS 0.2%CVE-2024-58267HIGHRancher CLI SAML authentication is vulnerable to phishing attacksEPSS 0.2%CVE-2024-52284HIGHRancher Fleet Helm Values are stored inside BundleDeployment in plain textEPSS 0.2%CVE-2025-46802MEDIUMTemporary chown() of users' TTY to mode 0666 allows PTY hijacking in screenEPSS 0.2%CVE-2026-25703HIGHPotential information leakage from manager /network/graph API in NeuVectorEPSS 0.2%CVE-2022-45153HIGHsaphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.slsEPSS 0.2%CVE-2026-44933HIGHPath Traversal in Plugin Loading in libzyppEPSS 0.2%CVE-2026-75036MEDIUMFleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessingEPSS 0.2%CVE-2022-31251MEDIUMslurm: %post for slurm-testsuite operates as root in user owned directoryEPSS 0.2%CVE-2024-22038MEDIUMDoS attacks, information leaks etc. with crafted Git repositories in obs-scm-bridgeEPSS 0.2%CVE-2024-22034MEDIUMCrafted projects can overwrite special files in the .osc config directoryEPSS 0.2%CVE-2026-71403MEDIUMRancher: Identity-field mutation in /v3/users allows account hijack via principal rebindEPSS 0.2%CVE-2025-71261HIGHHarvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSEPSS 0.2%CVE-2022-45155MEDIUMobs-service-go_modules: arbitrary directory deleteEPSS 0.2%CVE-2023-32199MEDIUMRancher user retains access to clusters despite Global Role removalEPSS 0.2%CVE-2026-75033HIGHRancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation SpoofingEPSS 0.2%