Vulnerabilidades en wazuh

73 resultados
Análisis Vexday

Wazuh apresenta 38 vulnerabilidades registradas, com 12 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Apenas 1 está sob exploração ativa (KEV) e 6 são críticas, sugerindo impacto moderado; a fraqueza dominante é CWE-476 (null pointer dereference), típica de falhas de validação que afetam disponibilidade.

CVE-2026-30893CRITICALWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerEPSS 0.6%CVE-2026-44255MEDIUMWazuh: Username Enumeration via Timing Side-ChannelEPSS 0.6%CVE-2026-44253MEDIUMWazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulationEPSS 0.6%CVE-2026-74044HIGHWazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster HelloEPSS 0.6%CVE-2023-42455HIGHWazuh vulnerable to user privilege escalationEPSS 0.6%CVE-2026-74046MEDIUMWazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip BombEPSS 0.6%CVE-2026-25790MEDIUMWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON ParserEPSS 0.6%CVE-2026-28221MEDIUMWazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64EPSS 0.6%CVE-2026-54083HIGHWazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionEPSS 0.6%CVE-2026-74039HIGHWazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_contextEPSS 0.6%CVE-2026-74038HIGHWazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent EnrollmentEPSS 0.5%CVE-2026-32983MEDIUMSSL/TLS Renegotiation DoS in Wazuh Manager authd serviceEPSS 0.5%CVE-2026-44252HIGHWazuh Manager dapi RBAC Bypass Allows Privilege EscalationEPSS 0.5%CVE-2025-15615MEDIUMWazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of ServiceEPSS 0.5%CVE-2026-44254MEDIUMWazuh: Stack Out-of-Bounds Write in remoted Decompression PathEPSS 0.5%CVE-2026-25772MEDIUMWazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer UnderflowEPSS 0.5%CVE-2026-44256MEDIUMWazuh: CRLF Log Injection via Unsanitized Basic-Auth UsernameEPSS 0.5%CVE-2026-41424HIGHWazuh: Privilege Escalation via Admin-Protection Bypass in update-user API EndpointEPSS 0.5%CVE-2026-41499MEDIUMWazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()EPSS 0.4%CVE-2026-44251MEDIUMWazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent messageEPSS 0.4%