Vulnerabilities in Wazuh
73 resultsVexday analysis
O Wazuh registra 8 vulnerabilidades na base, com 1 crítica (CVSS), mas nenhuma sob exploração ativa confirmada. Não há publicações recentes (últimos 90 dias), indicando risco legado estável. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de implementação, sem evidência de exploração em campanha.
CVE-2026-46343HIGHWazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()EPSS 0.4%CVE-2026-54085HIGHWazuh: Missing input validation in multiple active response scripts allows argument injectionEPSS 0.4%CVE-2025-62785MEDIUMWazuh fillData NULL pointer dereference causes analysisd crashEPSS 0.4%CVE-2026-61783HIGHWazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.keyEPSS 0.4%CVE-2026-33434MEDIUMWazuh: Rate Limit Bypass via /events EndpointEPSS 0.4%CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2025-62789MEDIUMWazuh vulnerable to NULL pointer dereference in fim_alert line 712EPSS 0.4%CVE-2025-62790MEDIUMWazuh vulnerable to NULL pointer dereference in fim_fetch_attributes_stateEPSS 0.4%CVE-2026-32984MEDIUMHeap buffer overflow in wazuh-authdEPSS 0.4%CVE-2025-62787LOWWazuh Vulnerable to Heap-based Buffer Over-read in DecodeWinevtEPSS 0.4%CVE-2026-34150HIGHWazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsingEPSS 0.4%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.4%CVE-2025-59938MEDIUMHeap buffer overflow in wazuh-analysisdEPSS 0.4%CVE-2026-39359HIGHWazuh: Unauthenticated Path Traversal in authd via Agent Group NameEPSS 0.4%CVE-2025-64169MEDIUMWazuh NULL pointer dereference in fim_alert line 666EPSS 0.4%CVE-2025-62792MEDIUMWazuh vulnerable to Heap-based Buffer Over-read in w_expression_matchEPSS 0.4%CVE-2023-7340MEDIUMWazuh authd service (os_auth) Heap-based Buffer OverflowEPSS 0.3%CVE-2025-62791MEDIUMWazuh vulnerable to NULL pointer dereference in DecodeCiscatEPSS 0.3%CVE-2025-62788MEDIUMWazuh Vulnerable to Heap Use After Free in w_copy_event_for_logEPSS 0.3%CVE-2026-49392MEDIUMWazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckdEPSS 0.3%