wazuh
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 63 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 29, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Wazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync
Wazuh GitHub Actions Shell Injection via Fork Pull Request
Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node
Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message
Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)
Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name
Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing
Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)
Wazuh: Rate Limit Bypass via /events Endpoint
Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
Monitor wazuh in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.