Wazuh
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 90 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 29, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Wazuh Manager cluster header parsing allows pre-authentication memory exhaustion
Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Worker Thread Stack Exhaustion
Wazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/config
Wazuh cluster worker file sync allows arbitrary file write under /var/ossec (incomplete fix for CVE-2026-30893)
Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privilege users to read cluster.key
Wazuh agent enrollment NULL pointer dereference via malformed manager response
Wazuh: Missing input validation in multiple active response scripts allows argument injection
Wazuh: Path traversal in ip-customblock active response allows arbitrary file creation and deletion
Wazuh: Local SQL injection in FIM db due to path lookup interpolation in wazuh-syscheckd
Wazuh: CRLF Log Injection via Unsanitized Basic-Auth Username
Monitor Wazuh in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.