CVE-2025-64169
- EPSS 0.05%
- Veröffentlicht 21.11.2025 18:39:02
- Zuletzt bearbeitet 02.12.2025 16:28:06
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not check whether oldsum->md5 is NULL or not before dereferencing it. A compromised age...
CVE-2025-54866
- EPSS 0.01%
- Veröffentlicht 21.11.2025 18:23:49
- Zuletzt bearbeitet 02.12.2025 16:39:30
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "C:\Program Files (x86)\ossec-agent\authd.pass" exposes the password to all "Authenticated Users" on t...
CVE-2025-30201
- EPSS 0.18%
- Veröffentlicht 21.11.2025 18:17:37
- Zuletzt bearbeitet 02.12.2025 16:45:54
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various a...
CVE-2025-64483
- EPSS 0.04%
- Veröffentlicht 21.11.2025 17:55:33
- Zuletzt bearbeitet 25.11.2025 22:16:42
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent en...
CVE-2025-62792
- EPSS 0.06%
- Veröffentlicht 29.10.2025 16:50:05
- Zuletzt bearbeitet 03.11.2025 19:35:16
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being proper...
CVE-2025-62791
- EPSS 0.07%
- Veröffentlicht 29.10.2025 16:48:25
- Zuletzt bearbeitet 03.11.2025 19:34:46
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCiscat() implementation does not check the return the value of cJSON_GetObjectItem() for a possible NULL value in case of an error. A...
CVE-2025-62790
- EPSS 0.09%
- Veröffentlicht 29.10.2025 16:46:31
- Zuletzt bearbeitet 03.11.2025 19:34:22
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch_attributes_state() implementation does not check whether time_string is NULL or not before calling strlen() on it. A compromised ...
CVE-2025-62789
- EPSS 0.09%
- Veröffentlicht 29.10.2025 16:44:30
- Zuletzt bearbeitet 03.11.2025 19:36:59
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert() implementation does not check whether the return value of ctime_r is NULL or not before calling strdup() on it. A compromised a...
CVE-2025-62788
- EPSS 0.06%
- Veröffentlicht 29.10.2025 16:42:35
- Zuletzt bearbeitet 03.11.2025 19:36:29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memory (initially allocated in OS_CleanMSG()) after it has been freed. A compromised agent can potentiall...
CVE-2025-62787
- EPSS 0.06%
- Veröffentlicht 29.10.2025 16:30:26
- Zuletzt bearbeitet 03.11.2025 19:35:38
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect...