Suse / Neuvector
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-78424 | OS Command Injection in Packet-Capture (Sniffer) Filter leading to Remote Code Execution on Kubernetes Nodes | HIGH | 8.8 | Sep 28, 2026 |
| CVE-2026-78426 | Logout bypass via alternate JWT spelling | LOW | 2.0 | Sep 17, 2026 |
| CVE-2026-78428 | Flaw in Neuvector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently | HIGH | 8.8 | Sep 17, 2026 |
| CVE-2025-46808 | Sensitive information is leaked into NeuVector’s manager container logs | MEDIUM | 6.8 | Sep 9, 2026 |
| CVE-2026-25703 | Potential information leakage from manager /network/graph API in NeuVector | HIGH | 7.3 | Aug 5, 2026 |
| CVE-2025-66001 | NeuVector OpenID Connect is vulnerable to man-in-the-middle (MITM) | HIGH | 8.8 | Jan 8, 2026 |
| CVE-2025-54471 | NeuVector is shipping cryptographic material into its binary | MEDIUM | 6.5 | Oct 30, 2025 |
| CVE-2025-54469 | NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow | CRITICAL | 9.9 | Oct 30, 2025 |
| CVE-2025-54470 | NeuVector telemetry sender is vulnerable to MITM and DoS | HIGH | 8.6 | Oct 30, 2025 |
| CVE-2025-8077 | NeuVector admin account has insecure default password | CRITICAL | 9.8 | Sep 17, 2025 |
| CVE-2025-54467 | NeuVector process with sensitive arguments lead to leakage | MEDIUM | 5.3 | Sep 17, 2025 |
| CVE-2025-53884 | NeuVector has an insecure password storage vulnerable to rainbow attack | MEDIUM | 5.3 | Sep 17, 2025 |
| CVE-2023-32188 | JWT token compromise can allow malicious actions including Remote Code Execution (RCE) | CRITICAL | 9.4 | Oct 16, 2024 |
| CVE-2023-22644 | JWT token compromise can allow malicious actions including Remote Code Execution (RCE) | CRITICAL | 9.4 | Sep 20, 2023 |
Showing 1 to 12 of 12 CVEs