VYPR
Vendor

Wazuh

Products
14
CVEs
81
Across products
104
Status
Private

Products

14

Recent CVEs

81
View all 81 CVEs →
  • CVE-2025-24016CriKEVFeb 10, 2025
    risk 0.87cvss 9.9epss 0.94

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a…

  • CVE-2024-32038CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd when handling Unicode characters from Windows Eventchannel messages. It impacts Wazuh Manager 3.8.0 and above. This vulnerability is…

  • CVE-2021-44079CriNov 22, 2021
    risk 0.64cvss 9.8epss 0.03

    In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution.

  • CVE-2026-67308CriAug 1, 2026
    risk 0.60cvss —epss 0.01

    Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters into environment variables that are…

  • CVE-2023-50260HigApr 19, 2024
    risk 0.60cvss 8.8epss 0.41

    Wazuh is a free and open source platform used for threat prevention, detection, and response. A wrong validation in the `host_deny` script allows to write any string in the `hosts.deny` file, which can end in an arbitrary command execution on the target system. This…

  • CVE-2021-26814HigMar 6, 2021
    risk 0.58cvss 8.8epss 0.09

    Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code…

  • CVE-2026-25769CriMar 17, 2026
    risk 0.53cvss 9.1epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.0.0 through 4.14.2 have a Remote Code Execution (RCE) vulnerability due to Deserialization of Untrusted Data). All Wazuh deployments using cluster mode (master/worker…

  • CVE-2026-61800CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.01

    Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to…

  • CVE-2026-49441CriAug 19, 2026
    risk 0.52cvss 9.1epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.3.0 until 4.14.6 and 5.0.0-beta3, the non-merged branch of process_files_from_worker() in framework/wazuh/core/cluster/master.py trusts a peer-controlled file_path key from…

  • CVE-2026-48162CriAug 19, 2026
    risk 0.52cvss 9.1epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, DistributedAPI.send_tmp_file() in framework/wazuh/core/cluster/dapi/dapi.py joins an attacker-controlled tmp_file value to WAZUH_PATH without…

  • CVE-2026-48024CriAug 19, 2026
    risk 0.52cvss 9.1epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta3, cluster.unmerge_info() in framework/wazuh/core/cluster/cluster.py constructs paths from peer-controlled merge_type and name values in a merged…

  • CVE-2026-30893CriApr 29, 2026
    risk 0.52cvss 9.0epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary…

  • CVE-2026-25770CriMar 17, 2026
    risk 0.52cvss 9.1epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, a privilege escalation vulnerability exists in the Wazuh Manager's cluster synchronization protocol. The `wazuh-clusterd` service…

  • CVE-2024-35177HigFeb 3, 2025
    risk 0.51cvss 7.8epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of protecting workloads across on-premises, virtualized, containerized, and cloud-based environments. The wazuh-agent for Windows is vulnerable to a Local Privilege…

  • CVE-2018-19666HigNov 29, 2018
    risk 0.51cvss 7.8epss 0.01

    The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server.

  • CVE-2026-44252HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only API user with manager:read permission to retrieve the cluster key from the element in ossec.conf through GET…

  • CVE-2025-62792HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.12.0, a buffer over-read occurs in w_expression_match() when strlen() is called on str_test, because the corresponding buffer is not being properly NULL terminated during its…

  • CVE-2025-62791HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, DecodeCiscat() implementation does not check the return the value of cJSON_GetObjectItem() for a possible NULL value in case of an error. A compromised agent can cause…

  • CVE-2025-62790HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_fetch_attributes_state() implementation does not check whether time_string is NULL or not before calling strlen() on it. A compromised agent can cause a crash of…

  • CVE-2025-62789HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to 4.11.0, fim_alert() implementation does not check whether the return value of ctime_r is NULL or not before calling strdup() on it. A compromised agent can cause a crash of…