Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rancher Fleet HIGH 8.2
CVE-2026-44937

Potential forgery of webhook requests when using a unauthenticated webhook in SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before …

Fix: 0.12.15 / 0.13.11+
Fix from $1,950 2026-07-06
Rancher Fleet MEDIUM 5.0
CVE-2026-44936

Missing filtering when the helmRepoURLRegex field isn't set on a GitRepo resource in SUSE Rancher Fleet's bundle reader in 0.15 before 0.15.2, 0.14 b…

Fix: 0.12.15 / 0.13.11+
Fix from $1,600 2026-07-06
Rancher Fleet CRITICAL 9.9
CVE-2026-44935

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and …

Fix: 0.12.15 / 0.13.11+
Fix from $2,300 2026-07-02
Rancher HIGH 7.4
CVE-2026-44946

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, po…

Fix: 2.11.15 / 2.12.11+
Fix from $1,950 2026-06-30
Rancher HIGH 8.8
CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access …

Fix: 2.13.6 / 2.14.2+
Fix from $1,950 2026-06-30
Rancher HIGH 8.8
CVE-2026-41052

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 befor…

Fix: 2.12.10 / 2.13.6+
Fix from $1,950 2026-06-29
Local Path Provisioner HIGH 8.7
CVE-2026-44543

Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with perm…

Fix: 0.0.36+
Fix from $1,950 2026-05-28
Linux Enterprise Server CRITICAL 9.8
CVE-2026-25702

A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via…

Mitigation only
Fix from $2,300 2026-03-05
Pam Config HIGH 7.8
CVE-2025-6018

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw all…

No fix yet
Fix from $1,950 2025-07-23
Rancher MEDIUM 6.5
CVE-2023-22649

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://rancherm…

Fix: 2.6.14 / 2.7.10+
Fix from $1,600 2024-10-16
Rancher HIGH 8.8
CVE-2020-10676

In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace t…

Fix: 2.6.13 / 2.7.4+
Fix from $1,950 2023-12-12
Manager Server MEDIUM 5.5
CVE-2023-22644

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perf…

Fix: 4.2.50-150300.3.66.5 / 4.3.58-150400.3.46.4+
Fix from $1,600 2023-09-20
Rancher Rke2 HIGH 7.5
CVE-2023-32186

A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor p…

Fix: 1.24.17 / 1.25.13+
Fix from $1,950 2023-09-19
Rancher HIGH 8.8
CVE-2023-22648

A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logg…

Fix: 2.6.13 / 2.7.4+
Fix from $1,950 2023-06-01
Rancher HIGH 8.4
CVE-2022-43760

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SUSE Rancher allows users in some higher-pri…

Fix: 2.6.13 / 2.7.4+
Fix from $1,950 2023-06-01
Rancher HIGH 8.0
CVE-2023-22647

An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes…

Fix: 2.6.13 / 2.7.4+
Fix from $1,950 2023-06-01
Rancher CRITICAL 9.9
CVE-2023-22651

Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook…

Fix: after 2.7.2
Fix from $2,300 2023-05-04
Opensuse Factory MEDIUM 5.5
CVE-2022-45155

An Improper Handling of Exceptional Conditions vulnerability in obs-service-go_modules of openSUSE Factory allows attackers that can influence the ca…

Fix: 0.6.1+
Fix from $1,600 2023-03-15
Linux Enterprise Module For Sap Applications HIGH 7.8
CVE-2022-45153

An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux En…

No fix yet
Fix from $1,950 2023-02-15
Wrangler CRITICAL 9.8
CVE-2022-31249

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler of SUSE Rancher allows remote …

Fix: 0.7.4 / 0.8.5+
Fix from $2,300 2023-02-07
Rancher CRITICAL 9.8
CVE-2022-43755

A Insufficient Entropy vulnerability in SUSE Rancher allows attackers that gained knowledge of the cattle-token to continue abusing this even after t…

Fix: 2.6.10 / 2.7.1+
Fix from $2,300 2023-02-07
Rancher HIGH 8.8
CVE-2022-21953

A Missing Authorization vulnerability in of SUSE Rancher allows authenticated user to create an unauthorized shell pod and kubectl access in the loca…

Fix: 2.5.17 / 2.6.10+
Fix from $1,950 2023-02-07
Rancher HIGH 8.8
CVE-2022-43757

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact…

Fix: 2.5.17 / 2.6.10+
Fix from $1,950 2023-02-07
Rancher HIGH 8.8
CVE-2022-43759

A Improper Privilege Management vulnerability in SUSE Rancher, allows users with access to the escalate verb on PRTBs to escalate permissions for any…

Fix: 2.5.17 / 2.6.10+
Fix from $1,950 2023-02-07
Wrangler HIGH 7.5
CVE-2022-43756

A Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in SUSE Rancher allows remote atta…

Fix: 0.7.4 / 0.8.5+
Fix from $1,950 2023-02-07
Rancher MEDIUM 6.8
CVE-2022-43758

A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Rancher allows code execution for …

Fix: 2.5.17 / 2.6.10+
Fix from $1,600 2023-02-07
Manager Server MEDIUM 5.4
CVE-2022-43754

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Mod…

Fix: 4.2.10 / 4.3.2+
Fix from $1,600 2022-11-10
Rancher CRITICAL 9.9
CVE-2021-36782

A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Proj…

Fix: 2.5.16 / 2.6.7+
Fix from $2,300 2022-09-07
Rancher CRITICAL 9.9
CVE-2021-36783

A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project…

Fix: 2.5.13 / 2.6.4+
Fix from $2,300 2022-09-07
Rancher CRITICAL 9.1
CVE-2022-31247

An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project…

Fix: 2.5.16 / 2.6.7+
Fix from $2,300 2022-09-07