Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/wazuh-manager

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Wazuh wazuh-manager versions from 4.4.0 up to but not including 4.14.7 contain a denial of service vulnerability in the fdecompress_files() function of cluster.py. Authenticated cluster peers with a valid Fernet key can supply a malicious, highly compressed archive (zip bomb) without decompressed size limits, causing the master node's wazuh-clusterd process to exhaust memory and disrupt service.

Join the discussion

Wazuh wazuh-manager versions from 4.0.0 up to but not including 4.14.6 contain a path traversal vulnerability. This flaw allows authenticated cluster peers with a valid Fernet key to delete arbitrary directory contents by sending a specially crafted node name in the cluster hello payload. The vulnerability arises because the node name is not properly validated, enabling attackers to trigger the master's peer cleanup routine to remove files within directories writable by the wazuh user. The CVSS 4.0 score is 7.0, indicating a high severity vulnerability.

Join the discussion

Wazuh wazuh-manager versions 4.0.0 up to but not including 4.14.7 and version 5.0.0-beta2 contain a denial of service vulnerability. Authenticated attackers with allow_run_as enabled can exploit this by submitting deeply nested JSON structures to the POST /security/user/authenticate/run_as endpoint. This causes excessive CPU consumption, leading to denial of service for other API users.

Join the discussion

Wazuh Manager versions 4.0.0 up to but not including 4.14.6 contain a path traversal vulnerability. This flaw allows unauthenticated remote attackers to cause a denial of service by enrolling an agent with a specially crafted name containing dot-sequences such as "..". Exploitation leads to deletion of critical subdirectories in the parent queue directory, stopping all Wazuh services and requiring manual recovery.

Join the discussion

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack of renegotiation limits to consume CPU resources and render the authd service unavailable.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/wazuh-manager
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses