Vulnerabilidades em Wazuh
48 resultadosAnálise Vexday
O Wazuh registra 8 vulnerabilidades na base, com 1 crítica (CVSS), mas nenhuma sob exploração ativa confirmada. Não há publicações recentes (últimos 90 dias), indicando risco legado estável. A fraqueza dominante é leitura fora dos limites (CWE-125), típica de implementação, sem evidência de exploração em campanha.
CVE-2025-24016CRITICALRemote code execution in Wazuh serverEPSS 93.8%KEVCVE-2023-50260HIGHWazuh's vulnerability in host_deny AR script allows arbitrary command executionEPSS 41.2%CVE-2026-25769CRITICALWazuh Cluster vulnerable to Remote Code Execution via Insecure DeserializationEPSS 9.2%CVE-2025-15616HIGHWazuh Agent and Manager OS Command Injection and Untrusted Search PathEPSS 1.6%CVE-2024-32038CRITICALWazuh Analysis Engine Event Decoder Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-25770CRITICALWazuh has Privilege Escalation to Root via Cluster Protocol File WriteEPSS 1.0%CVE-2023-49275MEDIUMWazuh vulnerable to NULL Pointer Dereference in wazuh-analysisdEPSS 0.9%CVE-2025-30201HIGHWazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration CapabilitiesEPSS 0.8%CVE-2025-62786MEDIUMWazuh Vulnerable to Heap-based Buffer Out-Of-Bounds WRITE in decode_win_permissionsEPSS 0.7%CVE-2023-42455HIGHWazuh vulnerable to user privilege escalationEPSS 0.6%CVE-2024-1243CRITICALRemote code execution and local privilege escalation in Wazuh Windows agent via NetNTLMv2 hash theftEPSS 0.5%CVE-2025-15615MEDIUMWazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of ServiceEPSS 0.5%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.5%CVE-2026-25771MEDIUMWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication MiddlewareEPSS 0.5%CVE-2026-67308CRITICALWazuh GitHub Actions Shell Injection via Fork Pull RequestEPSS 0.5%CVE-2026-32983MEDIUMSSL/TLS Renegotiation DoS in Wazuh Manager authd serviceEPSS 0.4%CVE-2025-62785MEDIUMWazuh fillData NULL pointer dereference causes analysisd crashEPSS 0.4%CVE-2026-30893CRITICALWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerEPSS 0.4%CVE-2026-28220HIGHWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master nodeEPSS 0.4%CVE-2026-25790MEDIUMWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON ParserEPSS 0.4%