Vulnerabilities in wazuh
73 resultsVexday analysis
Wazuh apresenta 38 vulnerabilidades registradas, com 12 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Apenas 1 está sob exploração ativa (KEV) e 6 são críticas, sugerindo impacto moderado; a fraqueza dominante é CWE-476 (null pointer dereference), típica de falhas de validação que afetam disponibilidade.
CVE-2026-46343HIGHWazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()EPSS 0.4%CVE-2026-54085HIGHWazuh: Missing input validation in multiple active response scripts allows argument injectionEPSS 0.4%CVE-2025-62785MEDIUMWazuh fillData NULL pointer dereference causes analysisd crashEPSS 0.4%CVE-2026-61783HIGHWazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.keyEPSS 0.4%CVE-2026-33434MEDIUMWazuh: Rate Limit Bypass via /events EndpointEPSS 0.4%CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2025-62789MEDIUMWazuh vulnerable to NULL pointer dereference in fim_alert line 712EPSS 0.4%CVE-2025-62790MEDIUMWazuh vulnerable to NULL pointer dereference in fim_fetch_attributes_stateEPSS 0.4%CVE-2026-32984MEDIUMHeap buffer overflow in wazuh-authdEPSS 0.4%CVE-2025-62787LOWWazuh Vulnerable to Heap-based Buffer Over-read in DecodeWinevtEPSS 0.4%CVE-2026-34150HIGHWazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsingEPSS 0.4%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.4%CVE-2025-59938MEDIUMHeap buffer overflow in wazuh-analysisdEPSS 0.4%CVE-2026-39359HIGHWazuh: Unauthenticated Path Traversal in authd via Agent Group NameEPSS 0.4%CVE-2025-64169MEDIUMWazuh NULL pointer dereference in fim_alert line 666EPSS 0.4%CVE-2025-62792MEDIUMWazuh vulnerable to Heap-based Buffer Over-read in w_expression_matchEPSS 0.4%CVE-2023-7340MEDIUMWazuh authd service (os_auth) Heap-based Buffer OverflowEPSS 0.3%CVE-2025-62791MEDIUMWazuh vulnerable to NULL pointer dereference in DecodeCiscatEPSS 0.3%CVE-2025-62788MEDIUMWazuh Vulnerable to Heap Use After Free in w_copy_event_for_logEPSS 0.3%CVE-2026-49392MEDIUMWazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckdEPSS 0.3%