Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.76% | — | Roxy-wi | 15/3/2023 | 17/6/2026 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` folder using a payload `../../../../../tmp/test111_dev`. This issue has been fixed… | |
| Modificada | Alta (7.5) | 1.2% | — | Roxy-wi | 13/3/2023 | 17/6/2026 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerability that allows the inclusion of server-side files. This issue is fixed in version 6.3.5.0. | |
| Modificada | Alta (7.5) | 1.0% | — | Roxy-wi | 13/3/2023 | 17/6/2026 | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a patch for this issue. | |
| Modificada | Crítica (9.8) | 29% | 💥 Exploit | Roxy-wi | 15/7/2022 | 17/6/2026 | Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue. | |
| Modificada | Crítica (9.8) | 91% | 💥 Exploit | Roxy-wi | 8/7/2022 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py… | |
| Modificada | Crítica (9.8) | 53% | 💥 Exploit | Roxy-wi | 6/7/2022 | 17/6/2026 | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised… | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Roxy-wi | 6/7/2022 | 17/6/2026 | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0.… | |
| Modificada | Alta (8.8) | 1.5% | — | Roxy-wi | 7/8/2021 | 17/6/2026 | Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py. | |
| Modificada | Alta (8.8) | 0.94% | — | Roxy-wi | 7/8/2021 | 17/6/2026 | Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers. | |
| Modificada | Crítica (9.8) | 1.3% | — | Roxy-wi | 7/8/2021 | 17/6/2026 | Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication. |