Wazuh
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 86 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 29, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config
Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)
Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.key
Wazuh agent enrollment NULL pointer dereference via malformed manager response
Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd
Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username
Wazuh: Pre-auth stack-buffer-overflow in compare_wazuh_versions reachable from wazuh-authd (TCP/1515) via crafted enrollment V: field
Wazuh : peer-controlled metadata key in process_files_from_worker non-merged branch allows arbitrary file write under WAZUH_PATH on Wazuh manager
Wazuh: Privilege Escalation via Admin-Protection Bypass in update-user API Endpoint
Wazuh: Username Enumeration via Timing Side-Channel
Monitor Wazuh in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.