CVE-2026-32983
- EPSS 0.42%
- Veröffentlicht 27.03.2026 15:44:30
- Zuletzt bearbeitet 08.05.2026 15:16:36
Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renego...
CVE-2026-32984
- EPSS 0.29%
- Veröffentlicht 27.03.2026 15:02:47
- Zuletzt bearbeitet 26.05.2026 14:16:33
Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, ...
CVE-2026-25790
- EPSS 0.39%
- Veröffentlicht 17.03.2026 18:41:45
- Zuletzt bearbeitet 19.03.2026 17:14:09
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, multiple stack-based buffer overflows exist in the Security Configuration Assessment (SCA) decoder (`...
CVE-2026-25772
- EPSS 0.31%
- Veröffentlicht 17.03.2026 18:11:05
- Zuletzt bearbeitet 19.03.2026 17:15:43
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.14.3, a stack-based buffer overflow vulnerability exists in the Wazuh Database synchronization module (`wdb...
CVE-2026-25771
- EPSS 0.47%
- Veröffentlicht 17.03.2026 18:08:53
- Zuletzt bearbeitet 19.03.2026 14:58:04
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 and prior to version 4.14.3, a Denial of Service (DoS) vulnerability exists in the Wazuh API authentication middleware (`middlewar...
CVE-2026-25770
- EPSS 0.97%
- Veröffentlicht 17.03.2026 18:02:07
- Zuletzt bearbeitet 19.03.2026 17:11:26
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization protocol. ...
CVE-2026-25769
- EPSS 9.25%
- Veröffentlicht 17.03.2026 17:41:08
- Zuletzt bearbeitet 19.03.2026 17:18:30
Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluste...
CVE-2025-64169
- EPSS 0.31%
- Veröffentlicht 21.11.2025 18:39:02
- Zuletzt bearbeitet 02.12.2025 16:28:06
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to before 4.12.0, fim_alert() implementation does not check whether oldsum->md5 is NULL or not before dereferencing it. A compromised age...
CVE-2025-54866
- EPSS 0.15%
- Veröffentlicht 21.11.2025 18:23:49
- Zuletzt bearbeitet 02.12.2025 16:39:30
Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on "C:\Program Files (x86)\ossec-agent\authd.pass" exposes the password to all "Authenticated Users" on t...
CVE-2025-30201
- EPSS 0.69%
- Veröffentlicht 21.11.2025 18:17:37
- Zuletzt bearbeitet 02.12.2025 16:45:54
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various a...