Skip to main content

Vendor archive

suse CVEs

Beta · best-effort

1,190 CVEs tagged to vendor suse245 Critical, 421 High, 419 Medium, 105 Low, 0 Unrated.

CVE-2026-44937

Published Jul 6, 2026

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.5…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44936

Published Jul 6, 2026

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44935

Published Jul 2, 2026

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be u…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44946

Published Jun 30, 2026

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, potentially allowing person in t…

CVSS 9.5 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41053

Published Jun 30, 2026

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41052

Published Jun 29, 2026

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44543

Published May 28, 2026

Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25702

Published Mar 5, 2026

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-62879

Published Mar 4, 2026

A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67601

Published Feb 25, 2026

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6018

Published Jul 23, 2025

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local atta…

CVSS 7.8 · High
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2025-32463

Published Jun 30, 2025

Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

CVSS 9.3 · Critical
evidence mentions
8
Buzz score
78.5
KEV listedPublic PoC observed

CVE-2024-12086

Published Jan 14, 2025

A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a c…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-22649

Published Oct 16, 2024

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://ranchermanager.docs.rancher.com/how-to…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10676

Published Dec 12, 2023

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a dif…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22644

Published Sep 20, 2023

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuV…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,190 CVEsPage 1 of 48