Caas Platform
Vendor:
First CVE: Jan 3, 2018 · Active for 8 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Caas Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2018
8 years ago
Most Recent CVE
Apr 22, 2026
93 days ago
CVE Severity & Scoring
Caas Platform8 CVEs
25%
25%
38%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (87.5%)
Network1 (12.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2017-18017CRITICAL The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-a | Jan 3, 2018 | 9.8 | 60 | NO | NO |
CVE-2022-27239HIGH In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | Apr 27, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-3682HIGH The docker-kubic package in SUSE CaaS Platform 3.0 before 17.09.1_ce-7.6.1 provided access to an insecure API locally on the Kubernetes master node. | Jan 17, 2020 | 7.8 | 23 | NO | NO |
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence | Aug 10, 2018 | 3.3 | 17 | NO | NO |
CVE-2020-8029MEDIUM A Incorrect Permission Assignment for Critical Resource vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to gain access to the kublet key. This issue affects | Feb 11, 2021 | 4.0 | 16 | NO | NO |
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read | Jan 24, 2020 | 3.3 | 15 | NO | NO |
CVE-2020-8030MEDIUM A Insecure Temporary File vulnerability in skuba of SUSE CaaS Platform 4.5 allows local attackers to leak the bootstrapToken or modify the configuration file before it is processed | Feb 11, 2021 | 4.4 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
1 CVE
12.5% of CVEs· 97th percentile
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Caas Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.5 | 2 | 4.2 | 0.3% | 0 | 0 |
| 4.0 | 2 | 7.8 | 48.4% | 1 | 1 |
| 3.0 | 1 | 7.8 | 0.3% | 0 | 0 |
| 2.0 | 1 | 3.3 | 0.4% | 0 | 0 |
| 1.0 | 1 | 3.3 | 0.4% | 0 | 0 |