Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
929 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 1.1% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 17/6/2026 | 20/7/2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a vulnerability in Envoy's HTTP/2 downstream request processing allows an unauthenticated remote client to trigger excessive memory consumption, potentially resulting in OOM… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Nginx Proxy ManagerAI | 15/6/2026 | 17/6/2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request. | |
| Aplazada | Alta (8.1) | 0.49% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring… | |
| Aplazada | Alta (8.3) | 0.40% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. | |
| Aplazada | Media (6.1) | 0.26% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via… | |
| Aplazada | Alta (8.1) | 0.47% | — | HaproxyAINginxAIApacheAIKeepalivedAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else… | |
| Aplazada | Alta (8.8) | 0.52% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver… | |
| Aplazada | Media (4.3) | 0.29% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in an unrelated group —… | |
| Aplazada | Media (6.5) | 0.37% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(f'http://{server_ip}:{agent_port}/...'). The path component is… | |
| Aplazada | Media (6.1) | 0.25% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string concatenation with no escaping. The frontend… | |
| Aplazada | Media (4.9) | 0.40% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput, no LDAP escape — and… | |
| Aplazada | Crítica (9.9) | 0.79% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped,… | |
| Aplazada | Crítica (9.9) | 0.59% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The… | |
| Aplazada | Crítica (9.9) | 0.45% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip,… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to… | |
| Aplazada | Alta (8.5) | 0.35% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the server_ip form field.… | |
| Modificada | Media (6.7) | 0.15% | — | Fortinet FortiosFortinet Fortiproxy | 9/6/2026 | 23/7/2026 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through… | |
| Aplazada | Alta (7.7) | 1.7% | — | Nginxproxymanager Nginx Proxy ManagerAI | 8/6/2026 | 23/7/2026 | Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a… | |
| Pendiente de análisis | Alta (7.5) | 0.65% | — | Cloudfoundry Cf-auth-proxyAICloudfoundry Log-cache ReleaseAI | 1/6/2026 | 22/7/2026 | Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and platform component via minting a JWT that the cf-auth-proxy accepts as a valid logs.admin token. Affected versions: -… | |
| Aplazada | Alta (8.7) | 7.8% | — | Openwrt Luci-app-https-dns-proxyAI | 26/5/2026 | 24/7/2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the… | |
| Analizada | Alta (8.7) | 0.46% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 13/5/2026 | 29/6/2026 | When SSL profiles are configured on a virtual server, undisclosed traffic can cause the virtual server to stop processing new client connections. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.46% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 13/5/2026 | 29/6/2026 | When an SSL profile is configured on a virtual server on BIG-IP Virtual Edition (VE) without Intel QuickAssist Technology (QAT) or on BIG-IP hardware platforms with the database variable crypto.hwacceleration set to disabled, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note:… | |
| Aplazada | Crítica (9.4) | 0.72% | — | Oxyno-zeta S3-proxyAI | 11/5/2026 | 17/6/2026 | oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware and the bucket handler. The authentication middleware evaluates resource path patterns against the percent-encoded… | |
| Analizada | Baja (2.1) | 0.39% | — | Router-for-me Cliproxyapi | 7/5/2026 | 17/6/2026 | A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack… | |
| Aplazada | Media (5.3) | 0.39% | — | Envoyproxy EnvoyAI | 25/4/2026 | 17/6/2026 | A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. This manipulation causes injection. Remote exploitation of the attack is possible. Patch name:… |