CVE-2025-64483
- EPSS 0.22%
- Veröffentlicht 21.11.2025 17:55:33
- Zuletzt bearbeitet 15.04.2026 00:35:42
Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent en...
CVE-2025-62792
- EPSS 0.32%
- Veröffentlicht 29.10.2025 16:50:05
- Zuletzt bearbeitet 03.11.2025 19:35:16
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being proper...
CVE-2025-62791
- EPSS 0.28%
- Veröffentlicht 29.10.2025 16:48:25
- Zuletzt bearbeitet 03.11.2025 19:34:46
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCiscat() implementation does not check the return the value of cJSON_GetObjectItem() for a possible NULL value in case of an error. A...
CVE-2025-62790
- EPSS 0.34%
- Veröffentlicht 29.10.2025 16:46:31
- Zuletzt bearbeitet 03.11.2025 19:34:22
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch_attributes_state() implementation does not check whether time_string is NULL or not before calling strlen() on it. A compromised ...
CVE-2025-62789
- EPSS 0.34%
- Veröffentlicht 29.10.2025 16:44:30
- Zuletzt bearbeitet 03.11.2025 19:36:59
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert() implementation does not check whether the return value of ctime_r is NULL or not before calling strdup() on it. A compromised a...
CVE-2025-62788
- EPSS 0.27%
- Veröffentlicht 29.10.2025 16:42:35
- Zuletzt bearbeitet 03.11.2025 19:36:29
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memory (initially allocated in OS_CleanMSG()) after it has been freed. A compromised agent can potentiall...
CVE-2025-62787
- EPSS 0.33%
- Veröffentlicht 29.10.2025 16:30:26
- Zuletzt bearbeitet 03.11.2025 19:35:38
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect...
CVE-2025-62786
- EPSS 0.61%
- Veröffentlicht 29.10.2025 15:52:52
- Zuletzt bearbeitet 03.11.2025 19:33:58
Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writing a NULL byte 2 bytes before the start of the buffer allocated to deco...
CVE-2025-62785
- EPSS 0.37%
- Veröffentlicht 29.10.2025 15:37:43
- Zuletzt bearbeitet 03.11.2025 19:32:54
Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation does not check whether value is NULL or not before calling os_strdup() on it. A compromised agent can cause a crash of analysisd b...
CVE-2025-34294
- EPSS 0.02%
- Veröffentlicht 28.10.2025 15:48:15
- Zuletzt bearbeitet 19.12.2025 15:15:55
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates from a documentation-published Active Response example script. Please refer to this advisory ( https://github.com/wazuh/wazuh-docume...