Opensuse
2,679 CVEs tracked since 2007. Since Jan 2015, 25 of them reached CISA KEV.
Opensuse CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2015-01 | 46 | 0 |
| 2015-02 | 49 | 1 |
| 2015-03 | 24 | 0 |
| 2015-04 | 48 | 1 |
| 2015-05 | 14 | 0 |
| 2015-06 | 10 | 1 |
| 2015-07 | 38 | 4 |
| 2015-08 | 32 | 1 |
| 2015-09 | 4 | 0 |
| 2015-10 | 20 | 2 |
| 2015-11 | 14 | 0 |
| 2015-12 | 28 | 1 |
| 2016-01 | 43 | 0 |
| 2016-02 | 25 | 1 |
| 2016-03 | 39 | 1 |
| 2016-04 | 61 | 1 |
| 2016-05 | 43 | 4 |
| 2016-06 | 101 | 1 |
| 2016-07 | 22 | 0 |
| 2016-08 | null or fewer | |
| 2016-09 | 29 | 0 |
| 2016-10 | 7 | 0 |
| 2016-11 | null or fewer | |
| 2016-12 | 12 | 0 |
| 2017-01 | null or fewer | |
| 2017-02 | 21 | 0 |
| 2017-03 | 37 | 0 |
| 2017-04 | null or fewer | |
| 2017-05 | 6 | 0 |
| 2017-06 | null or fewer | |
| 2017-07 | 5 | 0 |
| 2017-08 | 5 | 0 |
| 2017-09 | 2 | 0 |
| 2017-10 | 12 | 0 |
| 2017-11 | null or fewer | |
| 2017-12 | 4 | 0 |
| 2018-01 | 4 | 0 |
| 2018-02 | null or fewer | |
| 2018-03 | 15 | 0 |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | 14 | 0 |
| 2018-07 | 11 | 0 |
| 2018-08 | 6 | 0 |
| 2018-09 | 17 | 0 |
| 2018-10 | 12 | 0 |
| 2018-11 | null or fewer | |
| 2018-12 | 32 | 0 |
| 2019-01 | null or fewer | |
| 2019-02 | 48 | 0 |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | 38 | 0 |
| 2019-06 | null or fewer | |
| 2019-07 | 94 | 0 |
| 2019-08 | 51 | 0 |
| 2019-09 | 57 | 0 |
| 2019-10 | 61 | 0 |
| 2019-11 | 88 | 1 |
| 2019-12 | 74 | 0 |
| 2020-01 | 76 | 0 |
| 2020-02 | 79 | 1 |
| 2020-03 | 39 | 0 |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | 80 | 0 |
| 2020-07 | null or fewer | |
| 2020-08 | 34 | 1 |
| 2020-09 | 88 | 0 |
| 2020-10 | 37 | 0 |
| 2020-11 | 42 | 3 |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | 5 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | 3 | 0 |
| 2021-06 | 5 | 0 |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | 4 | 0 |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | 6 | 0 |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | 5 | 0 |
Products
The products that kept showing up in Opensuse's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Opensuse.
- CVE-2026-48863Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service7.5
- CVE-2026-44941libzypp path traversal via "keyhint" in repomd.xml8.4
- CVE-2026-56004obs-service-tar_scm: command injection via mercurial handler10.0
- CVE-2026-25707Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp8.8
- CVE-2026-48864Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data7.8
- CVE-2026-9149Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file6.5
- CVE-2026-9150Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums6.5
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
- CVE-2026-25701An Insecure Temporary File vulnerability in openSUSE sdbootutil allows local users to pre-create a directory to achieve various effects like: * gain access to possible private information found...—
- CVE-2026-25506MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery7.7
- CVE-2025-62875Local DoS in OpenSMTPD via UNIX domain socket smtpd.sock5.5
- CVE-2025-53881SUSE-specific logrotate configuration allows escalation from mail user/group to root—
- CVE-2025-46810A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of openSUSE Tumbleweed traefik2 allows the traefik user to escalate to root. This issue affects Tumbleweed: from ? before 2....—
- CVE-2025-32463Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.9.3
- CVE-2024-49505XSS vulnerability found in OpenSuse MirrorCache6.1
The record
- Peak rank
- #1 in Jun 2016
- Busiest month shown
- Jun 2016, 101 CVEs
- Months with a KEV entry
- 16 since Jan 2015
- Monthly snapshots
- 133 since 2007