Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3045▲ 455 respecto a la semana anterior
Críticas / altas1424▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)389▲ 174 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.49% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in app/modules/config/config.py:462. This is tuple-membership, not substring… | |
| Aplazada | Alta (8.3) | 0.40% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unauthenticated /api/gpt. At time of publication, there are no publicly available patches. | |
| Aplazada | Media (6.1) | 0.26% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by rejecting strings containing https:// or http:// substrings, then constructs https://{request.host}{next_url} and the JS client redirects via… | |
| Aplazada | Alta (8.1) | 0.47% | — | HaproxyAINginxAIApacheAIKeepalivedAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator used on dozens of fields including SSH credential name, username, description, etc. Its if/elif/elif/else… | |
| Aplazada | Alta (8.8) | 0.52% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter directly into a config-version path that ends up at os.system(f"dos2unix -q {cfg}"). configver… | |
| Aplazada | Media (4.3) | 0.29% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in an unrelated group —… | |
| Aplazada | Media (6.5) | 0.37% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the URL path component verbatim into requests.get(f'http://{server_ip}:{agent_port}/...'). The path component is… | |
| Aplazada | Media (6.1) | 0.25% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw HTML by string concatenation with no escaping. The frontend… | |
| Aplazada | Media (4.9) | 0.40% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput, no LDAP escape — and… | |
| Aplazada | Crítica (9.9) | 0.79% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and the PUT / global / defaults variants) accept a JSON option field that is not validated, not escaped,… | |
| Aplazada | Crítica (9.9) | 0.59% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field that is passed straight through to config_mod.master_slave_upload_and_restart(...) as the destination path. The… | |
| Aplazada | Crítica (9.9) | 0.45% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip,… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PUT /smon/check (app/routes/smon/routes.py:117-138) gates only on roxywi_common.check_user_group_for_flask() — which validates that the caller has some group, not that the target check_id belongs to… | |
| Aplazada | Alta (8.5) | 0.35% | — | Roxy-wiAIHaproxyAINginxAIApacheAI+1 | 10/6/2026 | 17/6/2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, agent_action (app/routes/smon/agent_routes.py:166-179) has decorators @bp.post('/agent/action/<action>') and @jwt_required() only — no role check, no group ownership check on the server_ip form field.… | |
| Aplazada | Crítica (9.8) | 0.62% | — | KeepalivedAI | 18/7/2024 | 17/6/2026 | In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user. | |
| Modificada | Media (5.4) | 1.1% | — | KeepalivedFedoraproject Fedora | 26/11/2021 | 17/6/2026 | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property | |
| Modificada | Crítica (9.8) | 3.7% | — | KeepalivedDebian LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 8/11/2018 | 17/6/2026 | keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, because extract_status_code in lib/html.c has no validation of the status code and instead writes an unlimited amount of data to the heap. | |
| Modificada | Media (4.7) | 0.37% | — | Keepalived | 8/11/2018 | 17/6/2026 | keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the… | |
| Modificada | Alta (7.5) | 2.4% | — | Keepalived | 8/11/2018 | 17/6/2026 | keepalived 2.0.8 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information. | |
| Modificada | Media (4.7) | 0.50% | — | Keepalived | 8/11/2018 | 17/6/2026 | keepalived 2.0.8 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to… | |
| Modificada | Baja (3.6) | 0.37% | — | Keepalived | 20/5/2011 | 16/6/2026 | The pidfile_write function in core/pidfile.c in keepalived 1.2.2 and earlier uses 0666 permissions for the (1) keepalived.pid, (2) checkers.pid, and (3) vrrp.pid files in /var/run/, which allows local users to kill arbitrary processes by writing a PID to one of these files. |