Wazuh

Wazuh

69 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.75%
  • Veröffentlicht 19.08.2026 16:14:20
  • Zuletzt bearbeitet 19.08.2026 17:18:51

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type ...

  • EPSS 0.63%
  • Veröffentlicht 19.08.2026 16:13:15
  • Zuletzt bearbeitet 19.08.2026 17:18:51

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file v...

  • EPSS 0.72%
  • Veröffentlicht 19.08.2026 16:12:12
  • Zuletzt bearbeitet 19.08.2026 18:16:39

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster work...

  • EPSS 0.17%
  • Veröffentlicht 01.08.2026 12:22:18
  • Zuletzt bearbeitet 03.08.2026 19:16:50

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer messages, while validating only the agentid against the authenticated agent identity. This allows a low...

  • EPSS 0.56%
  • Veröffentlicht 01.08.2026 12:22:17
  • Zuletzt bearbeitet 03.08.2026 20:17:26

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into e...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 20.07.2026 15:26:13
  • Zuletzt bearbeitet 29.07.2026 15:37:36

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channe...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 17.07.2026 00:01:41
  • Zuletzt bearbeitet 20.07.2026 02:22:10

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os_crypto/shared/msgs.c:389 allows any enrolled Wazuh agent to crash the wazuh-r...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 16.07.2026 23:57:16
  • Zuletzt bearbeitet 20.07.2026 02:29:49

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. When e...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 16.07.2026 23:55:18
  • Zuletzt bearbeitet 20.07.2026 13:42:42

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affects the Wazuh Manager's enrollment daemon (authd) and synchronization daemon (r...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 16.07.2026 23:44:42
  • Zuletzt bearbeitet 20.07.2026 13:36:42

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-analysisd allows an unauthenticated remote attacker to crash the Wazuh manager...