-Infinity
0

Wazuh WazuhWazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory Sync

Risk 36
Severity
7
First published (updated )

Wazuh Wazuh workflowsWazuh GitHub Actions Shell Injection via Fork Pull Request

Risk 80
Severity
9.3
First published (updated )

Wazuh WazuhWazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node

Risk 72
Severity
9.1
First published (updated )

Wazuh WazuhWazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message

Risk 38
Severity
6.5
First published (updated )

Wazuh Wazuh agent for WindowsWazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wazuh WazuhWazuh: Unauthenticated Path Traversal in authd via Agent Group Name

Risk 43
Severity
7.5
First published (updated )

Wazuh wazuh-analysisdWazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing

Risk 43
Severity
7.5
First published (updated )

Wazuh WazuhWazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)

Risk 38
Severity
6.5
First published (updated )

Wazuh WazuhWazuh: Rate Limit Bypass via /events Endpoint

Risk 48
Severity
7.1
First published (updated )

Wazuh Wazuh ManagerWazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index

Risk 87
Severity
10
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wazuh WazuhWazuh - NULL Pointer Dereference in inventory_sync DataValue FlatBuffer Handling

Risk 34
Severity
7.1
First published (updated )

Wazuh WazuhWazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()

Risk 38
Severity
6.5
First published (updated )

Wazuh WazuhWazuh cluster sync path traversal in decompress_files() enables arbitrary file write and code execution from authenticated cluster peer

Risk 82
Severity
9.9
First published (updated )

Wazuh Wazuh (wazuh-remoted)Wazuh: Pre-auth stack-based buffer overflow in wazuh-remoted print_hex_string() due to signed char promotion on x86_64

Risk 54
Severity
8.2
First published (updated )

Wazuh WazuhWazuh: API brute-force protection bypass via race condition in login attempt tracking

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wazuh WazuhWazuh: Heap-based NULL WRITE Buffer Underflow in GetAlertData

Risk 32
Severity
5.5
First published (updated )

Wazuh Wazuh provisioning scripts and DockerfilesWazuh Provisioning Scripts / Build Infrastructure Improper Certificate Validation leading to MITM and RCE

Risk 75
Severity
6.3
First published (updated )

Wazuh WazuhWazuh GitHub Actions Workflow Exposure of Sensitive Credentials

Risk 52
Severity
8.3
First published (updated )

Wazuh Wazuh AgentWazuh Agent and Manager OS Command Injection and Untrusted Search Path

Risk 66
Severity
7.1
First published (updated )

Wazuh Wazuh ManagerWazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service

Risk 43
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Wazuh WazuhWazuh authd service (os_auth) Heap-based Buffer Overflow

Risk 26
Severity
5.3
First published (updated )

Wazuh Wazuh Manager (authd)SSL/TLS Renegotiation DoS in Wazuh Manager authd service

Risk 43
Severity
6.9
First published (updated )

Wazuh WazuhHeap buffer overflow in wazuh-authd

Risk 26
Severity
5.3
First published (updated )

Wazuh WazuhWazuh has Stack-Based Buffer Overflow in Security Configuration Assessment JSON Parser

Risk 66
Severity
7.2
First published (updated )

Wazuh WazuhWazuh Database Synchronization Vulnerable to Stack-based Buffer Overflow via snprintf Integer Underflow

Risk 66
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

wazuh/wazuhWazuh Vulnerable to Denial of Service via Synchronous I/O Blocking in Asynchronous Authentication Middleware

Risk 43
Severity
7.5
First published (updated )

Wazuh Wazuh ManagerWazuh has Privilege Escalation to Root via Cluster Protocol File Write

Risk 72
Severity
9.1
First published (updated )

wazuh/wazuhWazuh Cluster vulnerable to Remote Code Execution via Insecure Deserialization

Risk 72
Severity
9.1
First published (updated )

Wazuh WazuhWazuh NULL pointer dereference in fim_alert line 666

Risk 23
Severity
5.1
First published (updated )

Wazuh WazuhWazuh installation fails to protected authd.pass on Windows

Risk 32
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203