Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.49% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring… | |
| Aplazada | Alta (8.3) | 0.40% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. | |
| Aplazada | Media (6.1) | 0.26% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via… | |
| Aplazada | Alta (8.1) | 0.47% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wi Roxy WIAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else… | |
| Aplazada | Alta (8.8) | 0.52% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver… | |
| Aplazada | Media (4.3) | 0.29% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in an unrelated group —… | |
| Aplazada | Media (6.5) | 0.37% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(f'http://{server_ip}:{agent_port}/...'). The path component is… | |
| Aplazada | Media (6.1) | 0.25% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string concatenation with no escaping. The frontend… | |
| Aplazada | Media (4.9) | 0.40% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput, no LDAP escape — and… | |
| Aplazada | Crítica (9.9) | 0.79% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped,… | |
| Aplazada | Crítica (9.9) | 0.59% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The… | |
| Aplazada | Crítica (9.9) | 0.45% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip,… | |
| Aplazada | Crítica (9.1) | 0.34% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to… | |
| Aplazada | Alta (8.5) | 0.35% | — | ApacheAIHaproxyAIKeepalivedAIRoxy-wiAI | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the server_ip form field.… | |
| Analizada | Alta (7.4) | 0.91% | — | Roxy-wi | 24/4/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently executed on a remote… | |
| Analizada | Alta (8.9) | 0.52% | — | Roxy-wi | 24/4/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through multiple function… | |
| Analizada | Alta (7.7) | 0.54% | — | Roxy-wi | 24/4/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue. | |
| Analizada | Alta (8.9) | 1.0% | — | Roxy-wi | 24/4/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issue. | |
| Analizada | Alta (7.7) | 0.56% | — | Roxy-wi | 20/4/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without escaping LDAP special… | |
| Analizada | Media (5.7) | 0.49% | — | Roxy-wi | 20/4/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path to construct a local file path, which is subsequently opened and its contents… | |
| Analizada | Alta (8.8) | 3.0% | — | Roxy-wi | 18/3/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability exists in the `/config/compare/<service>/<server_ip>/show` endpoint, allowed authenticated users to execute arbitrary system commands on the app host. The vulnerability… | |
| Analizada | Alta (7.5) | 2.3% | — | Roxy-wi | 15/1/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py line 87, where the… | |
| Aplazada | Alta (8.7) | 18% | — | Roxy-wiAI | 3/1/2025 | 17/6/2026 | A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads to os command injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Alta (8.8) | 2.6% | — | Roxy-wi | 29/8/2024 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied input is used without validation when… | |
| Modificada | Media (6.5) | 0.90% | — | Roxy-wi | 17/4/2023 | 17/6/2026 | hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerability was found in the current version of Roxy-WI (6.3.9.0 at the moment of writing this report). The vulnerability can be exploited via an HTTP request to /app/options.py and the config_file_name… |