Opensuse Leap
4,390 CVEs tracked. 47 of them are in CISA KEV.
This hub aggregates every CVE we track for Opensuse Leap, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Opensuse Leap CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 81 |
| 2024-11 | 34 |
| 2024-12 | 89 |
| 2025-01 | 73 |
| 2025-02 | 33 |
| 2025-03 | 51 |
| 2025-04 | 44 |
| 2025-05 | 27 |
| 2025-06 | 48 |
| 2025-07 | 61 |
| 2025-08 | 25 |
| 2025-09 | 5 |
| 2025-10 | 12 |
| 2025-11 | 11 |
| 2025-12 | 2 |
| 2026-01 | 9 |
| 2026-02 | 2 |
| 2026-03 | 13 |
| 2026-04 | 3 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 4,390 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical414
- High1,970
- Medium1,836
- Low170
Latest CVEs
The 15 most recently published vulnerabilities affecting Opensuse Leap.
- CVE-2026-46243smb: client: reject userspace cifs.spnego descriptions7.1
- CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
- CVE-2026-22008Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with n...3.7
- CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
- CVE-2026-33636LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch647.6
- CVE-2026-33416LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`7.5
- CVE-2026-26740Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attacker to cause a denial of service via the EGifGCBToExtension overwriting an existing Graphic Control Extension block without vali...8.2
- CVE-2026-2921GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability7.8
- CVE-2026-3083GStreamer rtpqdm2depay Out-Of-Bounds Write Remote Code Execution Vulnerability8.8
- CVE-2026-3085GStreamer rtpqdm2depay Heap-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2026-2922GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability7.8
- CVE-2026-2920GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability7.8
- CVE-2026-31806FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions9.8
- CVE-2026-29776FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library3.1
- CVE-2026-3909Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)8.8
Product grouping is registry-driven, with AI assist and human review. How it works