roxy-wi Summary
Latest vulnerabilities published by roxy-wi
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)
CVE-2026-45569Roxy-wiRoxy-wi8.1HIGHRoxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt
CVE-2026-45567Roxy-wiRoxy-wi8.3HIGHRoxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypass
CVE-2026-45566Roxy-wiRoxy-wi6.1MEDIUMRoxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)
CVE-2026-45565Roxy-wiRoxy-wi8.1HIGHRoxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versions/.../save)
CVE-2026-45564Roxy-wiRoxy-wi8.8HIGHRoxy-WI: IDOR β any authenticated user can read another user's full action history
CVE-2026-45563Roxy-wiRoxy-wi4.3MEDIUMRoxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPs
CVE-2026-45561Roxy-wiRoxy-wi6.5MEDIUMRoxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped HTML)
CVE-2026-45560Roxy-wiRoxy-wi6.1MEDIUMRoxy-WI: LDAP injection in /user/ldap/<username> (admin-only)
CVE-2026-45559Roxy-wiRoxy-wi4.9MEDIUMRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section save
CVE-2026-45558Roxy-wiRoxy-wi9.9CRITICALRoxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`
CVE-2026-45556Roxy-wiRoxy-wi9.9CRITICALRoxy-WI: IDOR on PUT /smon/check β any user can rewrite any tenant's monitoring URL/IP/body
CVE-2026-45550Roxy-wiRoxy-wi9.1CRITICALRoxy-WI: Authorization bypass on POST /smon/agent/action/<action> β guest can stop or restart smon-agent on any host
CVE-2026-45549Roxy-wiRoxy-wi8.5HIGHRoxy-WI: Cross-tenant authorization bypass on /install/* β guest can run Ansible / SSH on every registered server
CVE-2026-45552Roxy-wiRoxy-wi9.9CRITICALRemote Code Execution Vulnerability in Roxy-WI by Roxy-WI
CVE-2026-33208Roxy-wiRoxy-wi7.4HIGHSQL Injection Vulnerability in Roxy-WI Web Management Interface
CVE-2026-33078Roxy-wiRoxy-wi8.9HIGHArbitrary File Read Vulnerability in Roxy-WI Web Interface for Server Management
CVE-2026-33077Roxy-wiRoxy-wi7.7HIGHRemote Code Execution Vulnerability in Roxy-WI Web Interface for Haproxy, Nginx, Apache, and Keepalived
CVE-2026-33076Roxy-wiRoxy-wi8.9HIGHLDAP Injection Vulnerability in Roxy-WI Web Interface by Roxy-WI
CVE-2026-33432Roxy-wiRoxy-wi7.7HIGHPath Traversal Vulnerability in Roxy-WI Web Interface for Server Management
CVE-2026-33431Roxy-wiRoxy-wi5.7MEDIUMCommand Injection Vulnerability in Roxy-WI Web Interface by Roxy-WI
CVE-2026-27811Roxy-wiRoxy-wi8.8HIGHCommand Injection Vulnerability in Roxy-WI Web Interface for Server Management
CVE-2026-22265Roxy-wiRoxy-wi7.5HIGHOS Command Injection Vulnerability in Roxy-WI by Roxy-WI Team
CVE-2024-13129Roxy-WI TeamRoxy-wiπΎπ‘8.7HIGHOS Command Injection Through Port Scanning on Roxy-WI Web Interface
CVE-2024-43804Roxy-wiRoxy-wi8.8HIGHSQL Injection Vulnerability in Roxy-WI by Hap-Wi
CVE-2021-38168Roxy-wiRoxy-wi8.8HIGH