Wazuh

Wazuh

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 21.11.2025 18:39:02
  • Zuletzt bearbeitet 02.12.2025 16:28:06

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not check whether oldsum->md5 is NULL or not before dereferencing it. A compromised age...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 21.11.2025 18:23:49
  • Zuletzt bearbeitet 02.12.2025 16:39:30

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "C:\Program Files (x86)\ossec-agent\authd.pass" exposes the password to all "Authenticated Users" on t...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 21.11.2025 18:17:37
  • Zuletzt bearbeitet 02.12.2025 16:45:54

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various a...

  • EPSS 0.04%
  • Veröffentlicht 21.11.2025 17:55:33
  • Zuletzt bearbeitet 25.11.2025 22:16:42

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent en...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 29.10.2025 16:50:05
  • Zuletzt bearbeitet 03.11.2025 19:35:16

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being proper...

  • EPSS 0.07%
  • Veröffentlicht 29.10.2025 16:48:25
  • Zuletzt bearbeitet 03.11.2025 19:34:46

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCiscat() implementation does not check the return the value of cJSON_GetObjectItem() for a possible NULL value in case of an error. A...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 29.10.2025 16:46:31
  • Zuletzt bearbeitet 03.11.2025 19:34:22

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch_attributes_state() implementation does not check whether time_string is NULL or not before calling strlen() on it. A compromised ...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 29.10.2025 16:44:30
  • Zuletzt bearbeitet 03.11.2025 19:36:59

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert() implementation does not check whether the return value of ctime_r is NULL or not before calling strdup() on it. A compromised a...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 29.10.2025 16:42:35
  • Zuletzt bearbeitet 03.11.2025 19:36:29

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memory (initially allocated in OS_CleanMSG()) after it has been freed. A compromised agent can potentiall...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 29.10.2025 16:30:26
  • Zuletzt bearbeitet 03.11.2025 19:35:38

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect...