VYPR

Wazuh

by Wazuh

Source repositories

CVEs (80)

  • CVE-2025-62788HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, w_copy_event_for_log() references memory (initially allocated in OS_CleanMSG()) after it has been freed. A compromised agent can potentially compromise the integrity of…

  • CVE-2026-44901HigAug 19, 2026
    risk 0.48cvss 8.4epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, AffectedItemsWazuhResult.merge() in framework/wazuh/core/results.py trusts the sort_casting field in a cluster worker's JSON response. During a…

  • CVE-2023-42463HigJan 12, 2024
    risk 0.48cvss 7.4epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow a local privilege escalation. This vulnerability was patched in version 4.5.3.

  • CVE-2024-1243HigJun 11, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper input validation in the Wazuh agent for Windows prior to version 4.8.0 allows an attacker with control over the Wazuh server or agent key to configure the agent to connect to a malicious UNC path. This results in the leakage of the machine account NetNTLMv2 hash, which…

  • CVE-2026-54083HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.01

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem…

  • CVE-2026-41424HigAug 19, 2026
    risk 0.46cvss 8.2epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.9.0 until 4.10.4 and 4.14.6, PUT /security/users/{user_id} in api/api/controllers/security_controller.py passes request.get("user") instead of…

  • CVE-2026-71540HigSep 24, 2026
    risk 0.42cvss 7.5epss 0.00

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size declared in a 20-byte cluster…

  • CVE-2026-45798HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.5.0 until 4.14.6 and 5.0.0-beta2, compare_wazuh_versions() in src/shared/version_op.c copies the attacker-controlled enrollment V: field into a 10-byte stack buffer with…

  • CVE-2025-15617MedMar 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Wazuh version 4.12.0 contains an exposure vulnerability in GitHub Actions workflow artifacts that allows attackers to extract the GITHUB_TOKEN from uploaded artifacts. Attackers can use the exposed token within a limited time window to perform unauthorized actions such as…

  • CVE-2025-59938MedSep 27, 2025
    risk 0.42cvss 6.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from 3.8.0 to before 4.11.0, wazuh-analysisd is vulnerable to a heap buffer overflow when parsing XML elements from Windows EventChannel messages. This issue has…

  • CVE-2023-49275MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. A NULL pointer dereference was detected during fuzzing of the analysis engine, allowing malicious clients to DoS the analysis engine. The bug occurs when `analysisd` receives a…

  • CVE-2021-41821MedSep 29, 2021
    risk 0.42cvss 6.5epss 0.01

    Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

  • CVE-2026-46343HigAug 19, 2026
    risk 0.40cvss 7.2epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows a cluster-authenticated node to delete files outside…

  • CVE-2026-54085HigAug 28, 2026
    risk 0.39cvss 7.1epss 0.00

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response scripts pass attacker-influenced alert fields to privileged system commands without validating their…

  • CVE-2026-74038HigAug 18, 2026
    risk 0.39cvss 7.1epss 0.01

    Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrolling an agent with a dot-sequence name such as ".." through the enrollment port. Attackers exploit insufficient validation in…

  • CVE-2025-15616MedMar 27, 2026
    risk 0.37cvss 6.7epss 0.02

    Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags,…

  • CVE-2026-61811MedSep 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a depth limit while allocating…

  • CVE-2026-61802MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.01

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, a low-privilege API user can read the cleartext cluster key from a configuration endpoint that fails to redact it. The REST…

  • CVE-2026-61783MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege user can read the cluster secret from the manager configuration because the logic that masks…

  • CVE-2026-74044MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.01

    Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by supplying a traversal-shaped node name in the cluster hello payload without validation. Attackers holding a valid cluster Fernet…