Vulnerabilidades em Wazuh
71 resultadosAnálise Vexday
O Wazuh registra 8 vulnerabilidades na base, com 1 crítica (CVSS), mas nenhuma sob exploração ativa confirmada. Não há publicações recentes (últimos 90 dias), indicando risco legado estável. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de implementação, sem evidência de exploração em campanha.
CVE-2026-34150HIGHWazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsingEPSS 0.4%CVE-2025-59938MEDIUMHeap buffer overflow in wazuh-analysisdEPSS 0.4%CVE-2026-41424HIGHWazuh: Privilege Escalation via Admin-Protection Bypass in update-user API EndpointEPSS 0.4%CVE-2026-46343HIGHWazuh: Arbitrary File Deletion via Cluster Protocol – Incomplete Path Validation in end_receiving_file()EPSS 0.4%CVE-2026-39359HIGHWazuh: Unauthenticated Path Traversal in authd via Agent Group NameEPSS 0.4%CVE-2025-64169MEDIUMWazuh NULL pointer dereference in fim_alert line 666EPSS 0.4%CVE-2025-62792MEDIUMWazuh vulnerable to Heap-based Buffer Over-read in w_expression_matchEPSS 0.4%CVE-2026-54083HIGHWazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletionEPSS 0.4%CVE-2026-74046MEDIUMWazuh 4.4.0 < 4.14.7 DoS via fdecompress_files() Zip BombEPSS 0.3%CVE-2026-74039HIGHWazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_contextEPSS 0.3%CVE-2023-7340MEDIUMWazuh authd service (os_auth) Heap-based Buffer OverflowEPSS 0.3%CVE-2026-44256MEDIUMWazuh: CRLF Log Injection via Unsanitized Basic-Auth UsernameEPSS 0.3%CVE-2026-25772MEDIUMWazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer UnderflowEPSS 0.3%CVE-2025-62791MEDIUMWazuh vulnerable to NULL pointer dereference in DecodeCiscatEPSS 0.3%CVE-2025-62788MEDIUMWazuh Vulnerable to Heap Use After Free in w_copy_event_for_logEPSS 0.3%CVE-2026-49392MEDIUMWazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckdEPSS 0.3%CVE-2026-32984MEDIUMHeap buffer overflow in wazuh-authdEPSS 0.3%CVE-2024-35177HIGHImproper Access Control in wazuh-agentEPSS 0.3%CVE-2025-64483MEDIUMWazuh API – Agent Configuration Has Improper Access Control in Agent Enrollment EndpointEPSS 0.3%CVE-2026-41499MEDIUMWazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()EPSS 0.3%