Vulnerabilidades em SUSE

229 resultados
Análise Vexday

Com 193 CVEs catalogadas, o portfólio de vulnerabilidades da SUSE apresenta uma taxa de exploração ativa abaixo da média geral do catálogo, sem nenhum registro no CISA KEV, o que sugere menor exposição imediata a ataques confirmados. Ainda assim, 26 falhas de severidade crítica merecem atenção contínua, especialmente CVE-2025-46811, que concentra o maior escore EPSS observado (0,1032) e representa o risco mais elevado de exploração no curto prazo. A falha mais recorrente por tipo é CWE-276 (permissões padrão incorretas), um padrão que frequentemente decorre de configurações inadequadas durante implantação ou atualização de pacotes. Com apenas 2 CVEs com PoC pública e 9 surgidas nos últimos 90 dias, equipes de segurança devem manter ciclos de patching ativos, priorizando as críticas e monitorando a evolução do EPSS para as mais recentes.

CVE-2026-55998MEDIUMCluster Existence Oracle via Unauthenticated Import EndpointEPSS 0.2%CVE-2026-25702HIGHnftables disabled due to incorrect kernel backportEPSS 0.2%CVE-2020-8017MEDIUMrace condition on texlive-filesystem cron job allows for the deletion of unintended filesEPSS 0.2%CVE-2023-32190HIGHmlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readableEPSS 0.2%CVE-2026-75035HIGHRancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypassEPSS 0.2%CVE-2025-46808MEDIUMSensitive information is leaked into NeuVector’s manager container logsEPSS 0.2%CVE-2026-75034HIGHRancher: SAML Assertion ReplayEPSS 0.2%CVE-2026-41054HIGHMissing exit out of permission check in haveged could lead to root exploitEPSS 0.2%CVE-2025-54470HIGHNeuVector telemetry sender is vulnerable to MITM and DoSEPSS 0.2%CVE-2026-71401MEDIUMwicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds readEPSS 0.2%CVE-2024-22029HIGHtomcat packaging allows for escalation to root from tomcat userEPSS 0.2%CVE-2025-62875MEDIUMLocal DoS in OpenSMTPD via UNIX domain socket smtpd.sockEPSS 0.2%CVE-2025-53884MEDIUMNeuVector has an insecure password storage vulnerable to rainbow attackEPSS 0.2%CVE-2022-45154MEDIUMsupportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.shEPSS 0.2%CVE-2024-22037MEDIUMDatabase password leaked by systemd uyuni-server-attestation serviceEPSS 0.2%CVE-2026-59674HIGHLPE from suricata user to root due to chown in %post in suricata packagingEPSS 0.2%CVE-2026-71402MEDIUMwicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total lengthEPSS 0.2%CVE-2025-67601HIGHRancher CLI skips TLS verification on Rancher CLI login commandEPSS 0.2%CVE-2026-44934HIGHExposed tokens in SUSE Rancher AI Agent logsEPSS 0.2%CVE-2025-23386HIGHgerbera: Privilege escalation from user gerbera to root because of insecure %post scriptEPSS 0.2%