Wazuh

Wazuh

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 21.11.2025 17:55:33
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the Wazuh API – Agent Configuration in certain configurations allows authenticated users with read-only API roles to retrieve agent en...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 29.10.2025 16:50:05
  • Zuletzt bearbeitet 03.11.2025 19:35:16

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being proper...

  • EPSS 0.28%
  • Veröffentlicht 29.10.2025 16:48:25
  • Zuletzt bearbeitet 03.11.2025 19:34:46

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCiscat() implementation does not check the return the value of cJSON_GetObjectItem() for a possible NULL value in case of an error. A...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 29.10.2025 16:46:31
  • Zuletzt bearbeitet 03.11.2025 19:34:22

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch_attributes_state() implementation does not check whether time_string is NULL or not before calling strlen() on it. A compromised ...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 29.10.2025 16:44:30
  • Zuletzt bearbeitet 03.11.2025 19:36:59

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert() implementation does not check whether the return value of ctime_r is NULL or not before calling strdup() on it. A compromised a...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 29.10.2025 16:42:35
  • Zuletzt bearbeitet 03.11.2025 19:36:29

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memory (initially allocated in OS_CleanMSG()) after it has been freed. A compromised agent can potentiall...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 29.10.2025 16:30:26
  • Zuletzt bearbeitet 03.11.2025 19:35:38

Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.10.2, a buffer over-read occurs in DecodeWinevt() when child_attr[p]->attributes[j] is accessed, because the corresponding index (j) is incorrect...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 29.10.2025 15:52:52
  • Zuletzt bearbeitet 03.11.2025 19:33:58

Wazuh is a free and open source platform used for threat prevention, detection, and response. A heap-based out-of-bounds WRITE occurs in decode_win_permissions, resulting in writing a NULL byte 2 bytes before the start of the buffer allocated to deco...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 29.10.2025 15:37:43
  • Zuletzt bearbeitet 03.11.2025 19:32:54

Wazuh is a free and open source platform used for threat prevention, detection, and response. fillData() implementation does not check whether value is NULL or not before calling os_strdup() on it. A compromised agent can cause a crash of analysisd b...

  • EPSS 0.02%
  • Veröffentlicht 28.10.2025 15:48:15
  • Zuletzt bearbeitet 19.12.2025 15:15:55

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the behavior originates from a documentation-published Active Response example script. Please refer to this advisory ( https://github.com/wazuh/wazuh-docume...