Vulnerabilidades en Wazuh
48 resultadosAnálisis Vexday
O Wazuh registra 8 vulnerabilidades na base, com 1 crítica (CVSS), mas nenhuma sob exploração ativa confirmada. Não há publicações recentes (últimos 90 dias), indicando risco legado estável. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de implementação, sem evidência de exploração em campanha.
CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2026-28221MEDIUMWazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64EPSS 0.4%CVE-2025-62789MEDIUMWazuh vulnerable to NULL pointer dereference in fim_alert line 712EPSS 0.4%CVE-2025-62790MEDIUMWazuh vulnerable to NULL pointer dereference in fim_fetch_attributes_stateEPSS 0.4%CVE-2025-62787LOWWazuh Vulnerable to Heap-based Buffer Over-read in DecodeWinevtEPSS 0.4%CVE-2026-44251MEDIUMWazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent messageEPSS 0.4%CVE-2025-62792MEDIUMWazuh vulnerable to Heap-based Buffer Over-read in w_expression_matchEPSS 0.4%CVE-2025-64169MEDIUMWazuh NULL pointer dereference in fim_alert line 666EPSS 0.4%CVE-2025-59938MEDIUMHeap buffer overflow in wazuh-analysisdEPSS 0.3%CVE-2023-7340MEDIUMWazuh authd service (os_auth) Heap-based Buffer OverflowEPSS 0.3%CVE-2026-25772MEDIUMWazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer UnderflowEPSS 0.3%CVE-2025-62791MEDIUMWazuh vulnerable to NULL pointer dereference in DecodeCiscatEPSS 0.3%CVE-2025-62788MEDIUMWazuh Vulnerable to Heap Use After Free in w_copy_event_for_logEPSS 0.3%CVE-2026-32984MEDIUMHeap buffer overflow in wazuh-authdEPSS 0.3%CVE-2026-39359HIGHWazuh: Unauthenticated Path Traversal in authd via Agent Group NameEPSS 0.3%CVE-2026-33434MEDIUMWazuh: Rate Limit Bypass via /events EndpointEPSS 0.3%CVE-2024-35177HIGHImproper Access Control in wazuh-agentEPSS 0.3%CVE-2026-34150HIGHWazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsingEPSS 0.3%CVE-2026-41499MEDIUMWazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()EPSS 0.3%CVE-2025-64483MEDIUMWazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment EndpointEPSS 0.3%