CVE Tools

Suse

1,185 CVEs tracked since 1999. Since Apr 2015, 18 of them reached CISA KEV.

Suse CVEs per month

Apr 2015 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Suse CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-04360
2015-0530
2015-0631
2015-07104
2015-0831
2015-0910
2015-1042
2015-1160
2015-1231
2016-01null or fewer
2016-0241
2016-03211
2016-04281
2016-0584
2016-06701
2016-0770
2016-08null or fewer
2016-0990
2016-1020
2016-11null or fewer
2016-1210
2017-01null or fewer
2017-0240
2017-03110
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-0730
2017-0820
2017-09null or fewer
2017-10110
2017-11null or fewer
2017-1230
2018-0120
2018-02null or fewer
2018-03130
2018-04null or fewer
2018-05null or fewer
2018-0660
2018-0740
2018-0820
2018-09null or fewer
2018-1080
2018-11null or fewer
2018-1230
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-0520
2019-06null or fewer
2019-0730
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-1130
2019-1280
2020-01210
2020-02230
2020-03170
2020-04null or fewer
2020-05null or fewer
2020-0640
2020-07null or fewer
2020-0820
2020-0920
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-0230
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-0640
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-1230
2022-0131
2022-02null or fewer
2022-03null or fewer
2022-0440
2022-0550
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-0940
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02110
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-0940
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10150
2024-11110
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04100
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-0950
2025-10100
2025-1150
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05180
2026-06120
2026-0780
2026-08null or fewer
2026-09140

Products

The products that kept showing up in Suse's monthly top three, with their CVEs summed over those months.

  1. Linux Enterprise Server11124 months
  2. Linux Enterprise Desktop9218 months
  3. Linux Enterprise619 months
  4. Rancher5712 months
  5. Linux Enterprise Software Development Kit5512 months
  6. Suse Linux Enterprise Desktop394 months
  7. Linux Enterprise Workstation Extension371 month
  8. Package Hub315 months
  9. Suse Linux Enterprise Server267 months
  10. Linux Enterprise Debuginfo258 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Suse.

  1. CVE-2026-44940Service token exposure and potential privilege escalation in SUSE Observability5.7
  2. CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont29.0
  3. CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont29.0
  4. CVE-2025-46808Sensitive information is leaked into NeuVector’s manager container logs6.8
  5. CVE-2026-75036Fleet: DNS exfiltration via Sprig getHostByName in fleet.yaml Helm template preprocessing—
  6. CVE-2026-75035Rancher: ext.cattle.io/v1 Token store: cross-user token disclosure via label-selector scoping bypass7.7
  7. CVE-2026-75034Rancher: SAML Assertion Replay7.4
  8. CVE-2026-75033Rancher: Cross-Cluster Secret Leakage via Namespace projectId Annotation Spoofing7.7
  9. CVE-2026-71404Rancher: Ownership-less ClusterRole overwrite via attacker-controlled cr-name annotation on GlobalRole8.7
  10. CVE-2026-71403Rancher: Identity-field mutation in /v3/users allows account hijack via principal rebind6.1
  11. CVE-2026-13348CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number ...5.3
  12. CVE-2026-25706yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Active Directory-supplied)7.5
  13. CVE-2026-59681yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName in AD join8.8
  14. CVE-2026-59680yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute8.0
  15. CVE-2026-71402wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length5.4

The record

Peak rank
#3 in Dec 2004
Busiest month shown
Jun 2016, 70 CVEs
Months with a KEV entry
11 since Apr 2015
Monthly snapshots
168 since 1999
Suse's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store