📦 Wazuh

by Wazuh

🔍 What is Wazuh?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-32038

CRITICAL CVSS 9.8 Apr 19, 2024

A buffer overflow vulnerability in Wazuh Manager's analysisd component allows remote code execution when processing Unicode characters from Windows Eventchannel messages. This affects Wazuh Manager ve...

CVE-2021-44079

CRITICAL CVSS 9.8 Nov 22, 2021

CVE-2021-44079 is a command injection vulnerability in Wazuh's wazuh-slack active response script that allows remote code execution by passing untrusted user agents to curl commands. This affects Wazu...

CVE-2025-30201

HIGH CVSS 7.7 Nov 21, 2025

This vulnerability in Wazuh Agent allows authenticated attackers to force NTLM authentication through malicious UNC paths in agent configuration settings. This could lead to NTLM relay attacks resulti...

CVE-2025-62792

HIGH CVSS 7.5 Oct 29, 2025

A buffer over-read vulnerability in Wazuh allows compromised agents or attackers who can send crafted messages to the Wazuh manager to read beyond allocated memory boundaries, potentially accessing se...

CVE-2025-62787

HIGH CVSS 7.5 Oct 29, 2025

A buffer over-read vulnerability in Wazuh's DecodeWinevt() function allows compromised agents to trigger read operations beyond allocated buffer boundaries. Attackers can exploit this by sending speci...

CVE-2025-62788

HIGH CVSS 7.5 Oct 29, 2025

This is a use-after-free vulnerability in Wazuh's w_copy_event_for_log() function that allows compromised agents to send specially crafted messages to the manager. An attacker can potentially corrupt ...

CVE-2025-62790

HIGH CVSS 7.5 Oct 29, 2025

A NULL pointer dereference vulnerability in Wazuh's analysisd component allows a compromised agent to crash the manager by sending a specially crafted message. This causes denial of service, making th...

CVE-2025-62785

HIGH CVSS 7.5 Oct 29, 2025

A NULL pointer dereference vulnerability in Wazuh's fillData() function allows compromised agents to crash the analysisd service by sending specially crafted messages. This causes denial of service to...

CVE-2025-62786

HIGH CVSS 8.1 Oct 29, 2025

A heap-based out-of-bounds write vulnerability in Wazuh's decode_win_permissions function allows writing a NULL byte before an allocated buffer. Compromised agents or attackers sending crafted message...

CVE-2024-35177

HIGH CVSS 7.8 Feb 3, 2025

This CVE describes a local privilege escalation vulnerability in Wazuh Windows agent where improper ACLs on non-default installation directories allow local attackers to place malicious DLLs or replac...

CVE-2023-50260

HIGH CVSS 8.8 Apr 19, 2024

This vulnerability in Wazuh's host_deny script allows attackers to inject arbitrary commands into the /etc/hosts.deny file, leading to arbitrary command execution. It affects Wazuh servers and agents,...

CVE-2025-64169

MEDIUM CVSS 4.9 Nov 21, 2025

This vulnerability allows a compromised Wazuh agent to crash the analysisd service on the Wazuh manager by sending a specially crafted message. It affects Wazuh deployments running versions 3.7.0 thro...

CVE-2025-54866

MEDIUM CVSS 5.5 Nov 21, 2025

This vulnerability exposes the Wazuh agent authentication password file to all authenticated users on Windows systems, allowing local attackers to read the password. It affects Wazuh installations on ...

CVE-2024-47770

MEDIUM CVSS 4.6 Feb 3, 2025

This vulnerability in Wazuh allows attackers with no privilege access to view the agent list on the Wazuh dashboard, potentially enabling privilege escalation through information disclosure. All Wazuh...