Vulnerabilidades em wazuh

48 resultados
Análise Vexday

Wazuh apresenta 38 vulnerabilidades registradas, com 12 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Apenas 1 está sob exploração ativa (KEV) e 6 são críticas, sugerindo impacto moderado; a fraqueza dominante é CWE-476 (null pointer dereference), típica de falhas de validação que afetam disponibilidade.

CVE-2025-24016CRITICALRemote code execution in Wazuh serverEPSS 93.8%KEVCVE-2023-50260HIGHWazuh's vulnerability in host_deny AR script allows arbitrary command executionEPSS 41.2%CVE-2026-25769CRITICALWazuh Cluster vulnerable to Remote Code Execution via Insecure DeserializationEPSS 9.2%CVE-2025-15616HIGHWazuh Agent and Manager OS Command Injection and Untrusted Search PathEPSS 1.6%CVE-2024-32038CRITICALWazuh Analysis Engine Event Decoder Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-25770CRITICALWazuh has Privilege Escalation to Root via Cluster Protocol File WriteEPSS 1.0%CVE-2023-49275MEDIUMWazuh vulnerable to NULL Pointer Dereference in wazuh-analysisdEPSS 0.9%CVE-2025-30201HIGHWazuh NetNTLMv2 Hash Theft In Multiple Centralized Configuration CapabilitiesEPSS 0.8%CVE-2025-62786MEDIUMWazuh Vulnerable to Heap-based Buffer Out-Of-Bounds WRITE in decode_win_permissionsEPSS 0.7%CVE-2023-42455HIGHWazuh vulnerable to user privilege escalationEPSS 0.6%CVE-2024-1243CRITICALRemote code execution and local privilege escalation in Wazuh Windows agent via NetNTLMv2 hash theftEPSS 0.5%CVE-2025-15615MEDIUMWazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of ServiceEPSS 0.5%CVE-2026-33754MEDIUMWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)EPSS 0.5%CVE-2026-25771MEDIUMWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication MiddlewareEPSS 0.5%CVE-2026-67308CRITICALWazuh GitHub Actions Shell Injection via Fork Pull RequestEPSS 0.5%CVE-2026-32983MEDIUMSSL/TLS Renegotiation DoS in Wazuh Manager authd serviceEPSS 0.4%CVE-2025-62785MEDIUMWazuh fillData NULL pointer dereference causes analysisd crashEPSS 0.4%CVE-2026-30893CRITICALWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peerEPSS 0.4%CVE-2026-28220HIGHWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master nodeEPSS 0.4%CVE-2026-25790MEDIUMWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON ParserEPSS 0.4%