Vulnerabilidades em wazuh
71 resultadosAnálise Vexday
Wazuh apresenta 38 vulnerabilidades registradas, com 12 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Apenas 1 está sob exploração ativa (KEV) e 6 são críticas, sugerindo impacto moderado; a fraqueza dominante é CWE-476 (null pointer dereference), típica de falhas de validação que afetam disponibilidade.
CVE-2026-74038HIGHWazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent EnrollmentEPSS 0.5%CVE-2026-44253MEDIUMWazuh: Cluster Protocol Memory Exhaustion (DoS) via unbounded receive_str allocation and div_msg_box accumulationEPSS 0.5%CVE-2026-25771MEDIUMWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication MiddlewareEPSS 0.5%CVE-2026-44251MEDIUMWazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent messageEPSS 0.4%CVE-2026-32983MEDIUMSSL/TLS Renegotiation DoS in Wazuh Manager authd serviceEPSS 0.4%CVE-2026-74044HIGHWazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster HelloEPSS 0.4%CVE-2026-44252HIGHWazuh Manager dapi RBAC Bypass Allows Privilege EscalationEPSS 0.4%CVE-2025-62785MEDIUMWazuh fillData NULL pointer dereference causes analysisd crashEPSS 0.4%CVE-2026-61802MEDIUMWazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/configEPSS 0.4%CVE-2026-33434MEDIUMWazuh: Rate Limit Bypass via /events EndpointEPSS 0.4%CVE-2026-30893CRITICALWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerEPSS 0.4%CVE-2026-28220HIGHWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master nodeEPSS 0.4%CVE-2026-25790MEDIUMWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON ParserEPSS 0.4%CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2026-28221MEDIUMWazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64EPSS 0.4%CVE-2025-62790MEDIUMWazuh vulnerable to NULL pointer dereference in fim_fetch_attributes_stateEPSS 0.4%CVE-2025-62789MEDIUMWazuh vulnerable to NULL pointer dereference in fim_alert line 712EPSS 0.4%CVE-2026-44254MEDIUMWazuh: Stack Out-of-Bounds Write in remoted Decompression PathEPSS 0.4%CVE-2025-62787LOWWazuh Vulnerable to Heap-based Buffer Over-read in DecodeWinevtEPSS 0.4%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.4%