Vulnerabilities in Wazuh
48 resultsVexday analysis
O Wazuh registra 8 vulnerabilidades na base, com 1 crítica (CVSS), mas nenhuma sob exploração ativa confirmada. Não há publicações recentes (últimos 90 dias), indicando risco legado estável. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de implementação, sem evidência de exploração em campanha.
CVE-2024-47770MEDIUMAbility to view Agent list with no privilege access in wazuh-dashboardEPSS 0.2%CVE-2023-42463HIGHwazuh-logcollector integer underflow local privilege escalationEPSS 0.2%CVE-2025-15612MEDIUMWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCEEPSS 0.2%CVE-2026-26206MEDIUMWazuh: API brute-force protection bypass via race condition in login attempt trackingEPSS 0.2%CVE-2026-26204MEDIUMWazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertDataEPSS 0.2%CVE-2026-67307HIGHWazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory SyncEPSS 0.2%CVE-2025-54866LOWWazuh installation fails to protected authd.pass on WindowsEPSS 0.2%CVE-2026-40106MEDIUMWazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)EPSS 0.1%