Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

SUSE

First CVE: Oct 8, 1996Active for: 30 yearsTotal CVEs: 1,225
70.6
VTI Score
TOP TARGET

SUSE maintains a vulnerability footprint spanning its enterprise Linux distributions and development platforms, which are widely deployed across data centers and critical infrastructure and contribute substantially to the broader Linux security landscape. The vendor's disclosures reflect both inherited upstream kernel and library vulnerabilities and those originating in its own packaging and integration layers, with a moderate tendency toward critical-severity outcomes and an elevated propensity for public exploit code availability. Vulnerability exposure concentrates across its flagship Linux Enterprise Server, Desktop, and Software Development Kit products and recurs through memory-safety weakness classes including buffer-boundary violations, use-after-free conditions, and out-of-bounds writes that are characteristic of native-code components and kernel-level code paths. Defenders should treat SUSE advisories as broadly applicable to their Linux deployments, cross-reference upstream sources for context, and prioritize kernel and runtime-library updates; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
1,225
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
3.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by SUSE over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 8, 1996
29 years ago
Most Recent CVE
Jul 7, 2026
17 days ago

Self-Reporting Analysis

Of all the CVEs published by SUSE as a CNA, 50.0% affect products that SUSE develops as a vendor.

50.0%
50.0%
Self-reported: 122 (50.0%)
Third-party: 122 (50.0%)

Of all the CVEs published that affect products developed by SUSE, 10.0% are self-published by SUSE as a CNA.

90.0%
Self-published: 122 (10.0%)
Other CNAs: 1,103 (90.0%)

Products(121 total)

Top CVEs

Signals from CVEs in this vendor scope (1225 CVEs).

1,225 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31431HIGH
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2012-1823CRITICAL
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)
May 11, 20129.899YESYES
CVE-2021-4034HIGH
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pri
Jan 28, 20227.898YESYES
CVE-2016-4117CRITICAL
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016.
May 11, 20169.898YESYES
CVE-2016-3714HIGH
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to exec
May 5, 20168.498YESYES
CVE-2015-5122CRITICAL
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1
Jul 14, 20159.898YESYES
CVE-2015-5119CRITICAL
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows
Jul 8, 20159.898YESYES
CVE-2015-3113CRITICAL
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack
Jun 23, 20159.898YESYES
CVE-2015-0313CRITICAL
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta
Feb 2, 20159.898YESYES
View all 1,225 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,225 CVEs
8%
35%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local169 (13.8%)
Network404 (33.0%)
Unknown633 (51.7%)
Physical4 (0.3%)
Adjacent Network15 (1.2%)
Attack Complexity
Low530 (43.3%)
High62 (5.1%)
Unknown633 (51.7%)
User Interaction
None369 (30.1%)
Unknown633 (51.7%)
Required222 (18.1%)
Privileges Required
Low172 (14.0%)
High25 (2.0%)
None395 (32.2%)
Unknown633 (51.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (1225 CVEs).

CISA KEV
48 CVEs
3.9% of CVEs· 99th percentile
Metasploit
43 CVEs
3.5% of CVEs· 98th percentile
Nuclei
7 CVEs
0.6% of CVEs· 95th percentile
ExploitDB
154 CVEs
12.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by SUSE.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by SUSE — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For SUSE's Products

View all 22 CNAs →

Top CWEs