Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2021-41821

Disclosure Date: September 29, 2021 (last updated February 23, 2025)
Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.
Attacker Value
Unknown

CVE-2021-26814

Disclosure Date: March 06, 2021 (last updated February 22, 2025)
Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service script.
Attacker Value
Unknown

CVE-2018-19666

Disclosure Date: November 29, 2018 (last updated November 27, 2024)
The agent in OSSEC through 3.1.0 on Windows allows local users to gain NT AUTHORITY\SYSTEM access via Directory Traversal by leveraging full access to the associated OSSEC server.
0