VYPR

Wazuh Agent

by Wazuh

Source repositories

CVEs (4)

  • CVE-2024-1243HigJun 11, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which…

  • CVE-2025-15616MedMar 27, 2026
    risk 0.37cvss 6.7epss 0.02

    Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags,…

  • CVE-2026-40106MedJul 17, 2026
    risk 0.00cvss 4.7epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow vulnerability in the syscheck component of the Wazuh agent for Windows. When expanding registry paths…

  • CVE-2025-30201HigNov 21, 2025
    risk 0.00cvss 7.7epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in various agent configuration settings,…