vciy

CVEs we hold for Suse

Records whose assigning authority named Suse as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-75036Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessingSUSE Fleet
CVE-2026-75035Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypassSUSE Rancher
CVE-2026-75034Rancher: SAML Assertion ReplaySUSE Rancher
CVE-2026-75033Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation SpoofingSUSE Rancher
CVE-2026-71404Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRoleSUSE Rancher
CVE-2026-71403Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebindSUSE Rancher
CVE-2026-71402wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total lengthSUSE wicked
CVE-2026-71401wicked: integer underflow of the UDP length in ni_capture_inspect_udp_header() leads to an out-of-bounds readSUSE wicked
CVE-2026-59681yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD joinSUSE yast2-auth-client
CVE-2026-59680yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attributeSUSE yast2-users
CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont2SUSE openSUSE Tumbleweed; libXfont2
CVE-2026-59675Rancher Audit-Log Middleware Unauthenticated Memory Exhaustion Denial of ServiceSUSE Rancher
CVE-2026-59674LPE from suricata user to root due to chown in %post in suricata packagingSUSE openSUSE Tumbleweed
CVE-2026-55998Cluster Existence Oracle via Unauthenticated Import EndpointSUSE Rancher
CVE-2026-55996Unauthenticated Denial-of-Service via TLS SAN Stuffing in Rancher and cattle-cluster-agentSUSE Rancher
CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont2SUSE openSUSE Tumbleweed; libXfont
CVE-2026-44949Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhookSUSE Rancher
CVE-2026-44948Path Traversal in Rancher Fleet ImageScan GitRepo Path HandlerSUSE Rancher
CVE-2026-44947Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in RancherSUSE Rancher
CVE-2026-44946SAML Authentication Replay in RancherSUSE Rancher
CVE-2026-44945Cross-Cluster Impersonation Confused-Deputy Privilege EscalationSUSE Rancher
CVE-2026-44942libzypp .repo files can have an optional path which can lead to path traversal attacksSUSE libzypp
CVE-2026-44941libzypp path traversal via "keyhint" in repomd.xmlSUSE libzypp
CVE-2026-44940Service token exposure and potential privilege escalation in SUSE ObservabilitySUSE Observability
CVE-2026-44939Command injection through unsanitized YAML parameter in RancherSUSE Rancher
CVE-2026-44938Fleet has PSS Bypass through addLabelsFromOptions in Fleet AgentSUSE Rancher
CVE-2026-44937SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL ComponentsSUSE Rancher
CVE-2026-44936Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yamlSUSE Rancher
CVE-2026-44935Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm DeployerSUSE Rancher
CVE-2026-44934Exposed tokens in SUSE Rancher AI Agent logsSUSE Rancher
CVE-2026-44933Path Traversal in Plugin Loading in libzyppSUSE openSUSE
CVE-2026-44932indirect remote shell command injection via unsanitized DHCP options in wickedSUSE wicked
CVE-2026-41054Missing exit out of permission check in haveged could lead to root exploitSUSE Manager Server LTS 4.3
CVE-2026-41053Over-inclusive team membership expansion in GitHub App authentication provider for RancherSUSE Rancher
CVE-2026-41052Rancher Privilege Escalation from Project Owner to HostSUSE Rancher
CVE-2026-41051csync2 uses insecure temporary directories when compiled with C99 or laterSUSE openSUSE Tumbleweed
CVE-2026-41050Helm impersonation bypass of `RESTClientGetter` retains `cluster-admin` during template renderingSUSE Rancher
CVE-2026-25707Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzyppSUSE libzypp
CVE-2026-25706yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)SUSE yast2-samba-client
CVE-2026-25705Rancher Extensions have arbitrary file access via path traversalSUSE rancher
CVE-2026-25703Potential information leakage from manager /network/graph API in NeuVectorSUSE NeuVector
CVE-2026-25702nftables disabled due to incorrect kernel backportSUSE Linux Enterprise Server
CVE-2025-8671CVE-2025-8671SUSE Linux openSUSE Leap
CVE-2025-8412VMDP: Potential buffer overflow in the RtlQueryRegistryValues functionSUSE Virtual Machine Driver Pack
CVE-2025-8077NeuVector admin account has insecure default passwordSUSE neuvector
CVE-2025-71261Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOSSUSE Harvester
CVE-2025-67860NeuVector scanner insecurely handles passwords as command argumentsSUSE harvester
CVE-2025-67601Rancher CLI skips TLS verification on Rancher CLI login commandSUSE rancher
CVE-2025-66001NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM)SUSE neuvector
CVE-2025-62879Rancher Backup Operator pod's logs leak S3 tokensSUSE Rancher
CVE-2025-62878Local Path Provisioner vulnerable to Path Traversal via parameters.pathPatternSUSE Rancher
CVE-2025-62877Harvest may expose OS default ssh login password via SUSE Virtualization Interactive InstallerSUSE harvester
CVE-2025-62876no title heldSUSE openSUSE
CVE-2025-62875Local DoS in OpenSMTPD via UNIX domain socket smtpd.sockSUSE openSUSE Tumbleweed
CVE-2025-54471NeuVector is shipping cryptographic material into its binarySUSE neuvector
CVE-2025-54470NeuVector telemetry sender is vulnerable to MITM and DoSSUSE neuvector
CVE-2025-54469NeuVector Enforcer is vulnerable to Command Injection and Buffer overflowSUSE neuvector
CVE-2025-54468Rancher sends sensitive information to external services through the `/meta/proxy` endpointSUSE rancher
CVE-2025-54467NeuVector process with sensitive arguments lead to leakageSUSE neuvector
CVE-2025-53884NeuVector has an insecure password storage vulnerable to rainbow attackSUSE neuvector
CVE-2025-53883spacewalk-java has various XSS issues on search pageSUSE Manager Server LTS 4.3
CVE-2025-53882The logrotate configuration in the python-mailman of openSUSE allows the mailman user to sent SIGHUP to arbitrary…SUSE openSUSE Tumbleweed
CVE-2025-53880susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversalSUSE Manager Proxy LTS 4.3
CVE-2025-46811SUSE Multi Linux Manager allows code execution via unprotected websocket endpointSUSE Manager Server Module 4.3
CVE-2025-46809Multi Linux Manager epxoses the plain text HTTP Proxy user:password in logsSUSE Manager Server Module 4.3
CVE-2025-46808Sensitive information is leaked into NeuVector’s manager container logsSUSE neuvector
CVE-2025-46802Temporary chown() of users' TTY to mode 0666 allows PTY hijacking in screenSUSE Linux Enterprise High Performance Computing 15 SP6
CVE-2025-23394daily-backup.sh script in cyrus-imapd allows escalation from cyrus to rootSUSE openSUSE Tumbleweed
CVE-2025-23393Reflected XSS in spacewalk-javaSUSE Manager Server Module 4.3
CVE-2025-23392Reflected XSS in SystemsController.java in spacewalk-javaSUSE Manager Server Module 4.3
CVE-2025-23391Rancher: Restricted Administrator can change Administrator's passwordsSUSE rancher
CVE-2025-23389Rancher does not Properly Validate Account Bindings in SAML Authentication Enables User Impersonation on First LoginSUSE rancher
CVE-2025-23388Unauthenticated stack overflow in /v3-public/authproviders APISUSE rancher
CVE-2025-23387Rancher's SAML-based login via CLI can be denied by unauthenticated usersSUSE rancher
CVE-2025-23386gerbera: Privilege escalation from user gerbera to root because of insecure %post scriptSUSE openSUSE Tumbleweed
CVE-2024-58269Rancher exposes sensitive information through audit logsSUSE rancher
CVE-2024-58267Rancher CLI SAML authentication is vulnerable to phishing attacksSUSE rancher
CVE-2024-58260Rancher update on users can deny the service to the adminSUSE rancher
CVE-2024-58259Rancher affected by unauthenticated Denial of ServiceSUSE rancher
CVE-2024-52284Rancher Fleet Helm Values are stored inside BundleDeployment in plain textSUSE Rancher
CVE-2024-52283no title heldSUSE hackweek
CVE-2024-52282Rancher Helm Applications may have sensitive values leakedSUSE rancher
CVE-2024-52281Stored Cross-site Scripting vulnerability in Rancher UISUSE rancher
CVE-2024-52280Users can issue watch commands for arbitrary resourcesSUSE rancher
CVE-2024-49504grub2 allows bypassing TPM-bound disk encryption on SL(E)M encrypted ImagesSUSE openSUSE Tumbleweed
CVE-2024-49503Reflected XSS in Setup Wizard, Organization Credentials in spacewalk-webSUSE Manager Server Module 4.3
CVE-2024-49502Reflected XSS in Setup Wizard, HTTP Proxy credentials pane in spacewalk-webSUSE Manager Server Module 4.3
CVE-2024-22038DoS attacks, information leaks etc. with crafted Git repositories in obs-scm-bridgeSUSE openSUSE Factory
CVE-2024-22037Database password leaked by systemd uyuni-server-attestation serviceSUSE Manager Server 5.0
CVE-2024-22036Rancher Remote Code Execution via Cluster/Node DriversSUSE rancher
CVE-2024-22034Crafted projects can overwrite special files in the .osc config directorySUSE openSUSE Tumbleweed
CVE-2024-22033obs-service-download_url is vulnerable to argument injectionSUSE openSUSE Tumbleweed
CVE-2024-22032Rancher's RKE1 Encryption Config kept in plain-text within cluster AppliedSpecSUSE rancher
CVE-2024-22030Rancher agents can be hijacked by taking over the Rancher Server URLSUSE rancher
CVE-2024-22029tomcat packaging allows for escalation to root from tomcat userSUSE openSUSE Tumbleweed
CVE-2023-32199Rancher user retains access to clusters despite Global Role removalSUSE rancher
CVE-2023-32197Rancher's External RoleTemplates can lead to privilege escalationSUSE rancher
CVE-2023-32196Rancher's External RoleTemplates can lead to privilege escalationSUSE rancher
CVE-2023-32194Rancher permissions on 'namespaces' in any API group grants 'edit' permissions on namespaces in 'core'SUSE rancher
CVE-2023-32193Norman API Cross-site Scripting VulnerabilitySUSE norman
CVE-2023-32192Rancher API Server Cross-site Scripting VulnerabilitySUSE apiserver
CVE-2023-32191rke's credentials are stored in the RKE1 Cluster state ConfigMapSUSE rke
CVE-2023-32190mlocate's %post script allows RUN_UPDATEDB_AS user to make arbitrary files world readableSUSE openSUSE Tumbleweed
CVE-2023-32189Insecure handling SSH key in SUSE Manager when bootstrapping new clientsSUSE Manager Server Module 4.3
CVE-2023-32188JWT token compromise can allow malicious actions including Remote Code Execution (RCE)SUSE neuvector
CVE-2023-32187no title heldSUSE k3s
CVE-2023-32186no title heldSUSE RKE2
CVE-2023-32182no title heldSUSE openSUSE Leap 15.5
CVE-2023-22651no title heldSUSE Rancher
CVE-2023-22650Rancher does not automatically clean up a user deleted or disabled from the configured Authentication ProviderSUSE rancher
CVE-2023-22649Rancher 'Audit Log' leaks sensitive informationSUSE rancher
CVE-2023-22648no title heldSUSE Rancher
CVE-2023-22647no title heldSUSE Rancher
CVE-2023-22645kubewarden: Excessive permissions for kubewarden-controller-manager-cluster-roleSUSE kubewarden
CVE-2023-22644JWT token compromise can allow malicious actions including Remote Code Execution (RCE)SUSE neuvector
CVE-2023-22643libzypp-plugin-appdata: potential arbitrary code execution via shell injection due to `os.system` callsSUSE Linux Enterprise Server for SAP 15-SP3…
CVE-2022-45157Exposure of vSphere's CPI and CSI credentials in RancherSUSE rancher
CVE-2022-45155obs-service-go_modules: arbitrary directory deleteSUSE openSUSE Factory
CVE-2022-45154supportconfig does not remove passwords in /etc/iscsi/iscsid.conf and /etc/target/lio_setup.shSUSE Linux Enterprise Server 15 SP3
CVE-2022-45153saphanabootstrap-formula: Escalation to root for arbitrary users in hana/ha_cluster.slsSUSE Linux Enterprise Server for SAP 12-SP5…
CVE-2022-43760no title heldSUSE Rancher
CVE-2022-43759Rancher: Privilege escalation via promoted rolesSUSE Rancher
CVE-2022-43758Rancher: Command injection in Git packageSUSE Rancher
CVE-2022-43757Rancher: Exposure of sensitive fieldsSUSE Rancher
CVE-2022-43756Rancher/Wrangler: Denial of service when processing Git credentialsSUSE Rancher
CVE-2022-43755Rancher: Non-random authentication tokenSUSE Rancher
CVE-2022-43754SUMA/UYUNI reflected cross site scripting in /rhn/audit/scap/Search.doSUSE Manager Server 4.2
CVE-2022-43753SUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownloadSUSE Manager Server 4.2
CVE-2022-31256sendmail: mail to root privilege escalation via sm-client.pre scriptSUSE openSUSE Factory
CVE-2022-31255SUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewActionSUSE Manager Server 4.2
CVE-2022-31254rmt-server-pubcloud allows to escalate from user _rmt to rootSUSE Manager Server 4.1; openSUSE Leap 15.3…
CVE-2022-31252permissions: chkstat does not check for group-writable parent directories or target files in safeOpen()SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3…
CVE-2022-31251slurm: %post for slurm-testsuite operates as root in user owned directorySUSE openSUSE Factory
CVE-2022-31249[RANCHER] OS command injection in Rancher and FleetSUSE Rancher
CVE-2022-31248SUMA user enumeration via weak error messageSUSE Manager Server 4.2
CVE-2022-31247Rancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)SUSE Rancher
CVE-2022-21953Authenticated user can gain unauthorized shell pod and kubectl access in the local clusterSUSE Rancher
CVE-2022-21952SUMA unauthenticated remote DoS via resource exhaustionSUSE Manager Server 4.2
CVE-2022-21951Rancher: Weave CNI password is not set if RKE template is used with CNI value overriddenSUSE Rancher
CVE-2022-21949Multiple XXE vulnerabilities in OBSSUSE Open Build Service
CVE-2022-21947rancher desktop: Dashboard API is network accessibleSUSE Rancher
CVE-2021-46705grub2-once uses fixed file name in /var/tmpSUSE openSUSE Factory
CVE-2021-4200Write access to the Catalog for any user when restricted-admin role is enabledSUSE Rancher
CVE-2021-36784Privilege escalation for users with create/update permissions in Global RolesSUSE Rancher
CVE-2021-36783Rancher: Failure to properly sanitize credentials in cluster template answersSUSE Rancher
CVE-2021-36782Rancher: Plaintext storage and exposure of credentials in Rancher API and cluster.management.cattle.io objectSUSE Rancher
CVE-2021-36780Unauthorized data access from replicas through vulnerable instance manager podsSUSE Longhorn
CVE-2021-36779Host operations allowed in privileged Longhorn managed podsSUSE Longhorn
CVE-2021-36778Exposure of repository credentials to external third-party sourcesSUSE Rancher
CVE-2021-36776Steve API proxy impersonationSUSE Rancher
CVE-2021-36775Deleting PRTBs associated to a group doesn't cause deletion of corresponding RoleBindingsSUSE Rancher
CVE-2021-32001K3s/RKE2 bootstrap data is encrypted with empty string if user does not supply a tokenSUSE Rancher
CVE-2021-32000clone-master-clean-up: dangerous file system operationsSUSE Linux Enterprise Server 15 SP1; openSUSE Factory
CVE-2021-31998inn: %post calls user owned file allowing local privilege escalation to rootSUSE Linux Enterprise Server 11-SP3; openSUSE Backports…
CVE-2021-25321arpwatch: Local privilege escalation from runtime user to rootSUSE OpenStack Cloud Crowbar 9; openSUSE Factory…
CVE-2021-25317cups: ownership of /var/log/cups allows the lp user to create files as rootSUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2…
CVE-2021-25316Local DoS of VM live migration due to use of static tmp files in detach_disks.sh in s390-toolsSUSE Linux Enterprise Server 15-SP2
CVE-2021-25315salt-api unauthenticated remote code executionSUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed
CVE-2021-25314hawk: Insecure file permissionsSUSE Linux Enterprise High Availability 15-SP2
CVE-2021-25313Rancher: XSS on /v3/cluster/SUSE Rancher
CVE-2020-8030skuba: Insecure /tmp usage when joining node to clusterSUSE CaaS Platform 4.5
CVE-2020-8029skuba: Insecure handling of private keySUSE CaaS Platform 4.5
CVE-2020-8028salt-api is accessible to every user on SUSE Manager ServerSUSE Manager Server 4.0
CVE-2020-8027openldap uses fixed paths in /tmpSUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1…
CVE-2020-8025outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issuesSUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1…
CVE-2020-8023Local privilege escalation from ldap to root when using OPENLDAP_CONFIG_BACKEND=ldap in openldap2SUSE OpenStack Cloud Crowbar 8; openSUSE Leap 15.1…
CVE-2020-8022User-writeable configuration file /usr/lib/tmpfiles.d/tomcat.conf allows for escalation of priviligesSUSE OpenStack Cloud Crowbar 8
CVE-2020-8019syslog-ng: Local privilege escalation from new to root in %postSUSE Linux Enterprise Server for SAP 12-SP1…
CVE-2020-8018User owned /etc in SLES15-SP1-CHOST-BYOSSUSE Linux Enterprise Server 15 SP1
CVE-2020-8017race condition on texlive-filesystem cron job allows for the deletion of unintended filesSUSE Linux Enterprise Software Development Kit 12-SP5…
CVE-2020-8016race condition in the packaging of texlive-filesystenSUSE Linux Enterprise Software Development Kit 12-SP5…
CVE-2020-8013permissions: chkstat sets unintended setuid/capabilities for mrsh and wodimSUSE Linux Enterprise Server 11
CVE-2019-3698nagios cron job allows privilege escalation from user nagios to rootSUSE Linux Enterprise Server 11; openSUSE Factory
CVE-2019-3696pcp: Local privilege escalation from user pcp to root through migrate_tempdirsSUSE Linux Enterprise Software Development Kit 12-SP5…
CVE-2019-3695pcp: Local privilege escalation from user pcp to rootSUSE Linux Enterprise Software Development Kit 12-SP5…
CVE-2019-3693Local privilege escalation from user wwwrun to root in the packaging of mailmanSUSE Linux Enterprise Server 12; openSUSE Leap 15.1
CVE-2019-3692Local privilege escalation from user news to root in the packaging of innSUSE Linux Enterprise Server 11; openSUSE Factory…
CVE-2019-3691Local privilege escalation from user munge to rootSUSE Linux Enterprise Server 15; openSUSE Factory
CVE-2019-3690chkstat follows untrusted symbolic linksSUSE permissions
CVE-2019-3689nfs-utils: root-owned files stored in insecure /var/lib/nfs directorySUSE Linux Enterprise Server 15
CVE-2019-3688squid: /usr/sbin/pinger packaged with wrong permissionSUSE Linux Enterprise Server 12
CVE-2019-3687"easy" permission profile allows everyone execute dumpcap and read all network trafficSUSE Linux Enterprise Server
CVE-2019-3686XSS in distri and version parameter in openQASUSE openQA
CVE-2019-3684susemanager installer creates world-readable swap filesSUSE Manager; Uyuni
CVE-2019-3683keystone_json_assignment backend granted access to any project for users in user-project-map.jsonSUSE Openstack Cloud 8
CVE-2019-3682Insecure API port exposed to all Master Node guest containersSUSE CaaS Platform 3.0
CVE-2019-3681osc: stores downloaded (supposed) RPM in network-controlled filesystem pathsSUSE Linux Enterprise Software Development Kit 12-SP4…
CVE-2019-18906cryptctl: client side password hashing is equivalent to clear text password storageSUSE Manager Server 4.0
CVE-2019-18905Deprecated functionality in autoyast2 automatically imports gpg keys without checking themSUSE Linux Enterprise Server 15
CVE-2019-18904Migrations requests can cause DoS on rmtSUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1
CVE-2019-18903wicked: Use-after-free when receiving invalid DHCP6 IA_PD optionSUSE Linux Enterprise Server 15; openSUSE Leap 15.1…
CVE-2019-18902wicked: Use-after-free when receiving invalid DHCP6 client optionsSUSE Linux Enterprise Server 15; openSUSE Leap 15.1…
CVE-2019-18901mysql-systemd-helper allows setting 640 permissions of arbitrary filesSUSE Linux Enterprise Server 15
CVE-2019-18900libzypp stores cookies world readableSUSE Linux Enterprise Server 15
CVE-2019-18898trousers: Local privilege escalation from tss to rootSUSE Linux Enterprise Server 15 SP1; openSUSE Factory
CVE-2019-18897Local privilege escalation from user salt to rootSUSE Linux Enterprise Server 15; openSUSE Factory
CVE-2019-10220no title heldSUSE kernel:
CVE-2018-7685libzypp does not reevaluate malicious rpms once downloadedSUSE libzypp
CVE-2018-20106SMB printer settings don't escape characters in passwords properlySUSE yast2-printer
CVE-2018-20105yast2-rmt exposes CA private key passhrase in log-fileSUSE Linux Enterprise Server 15; openSUSE Leap

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.