Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Roxy Wi CRITICAL 9.8
CVE-2026-33076

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
Roxy Wi CRITICAL 9.8
CVE-2026-33078

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i…

Fix: 8.2.6.4+
Fix from $2,300 2026-04-24
Roxy Wi HIGH 8.8
CVE-2026-33208

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-co…

Fix: 8.2.6.4+
Fix from $1,950 2026-04-24
Roxy Wi HIGH 7.5
CVE-2026-33077

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the hapro…

Fix: 8.2.6.4+
Fix from $1,950 2026-04-24
Roxy Wi CRITICAL 9.1
CVE-2026-33432

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authenticat…

Fix: after 8.2.8.2
Fix from $2,300 2026-04-20
Roxy Wi MEDIUM 6.5
CVE-2026-33431

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API …

Fix: 8.2.6.4+
Fix from $1,600 2026-04-20
Roxy Wi HIGH 8.8
CVE-2026-27811

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex…

Fix: 8.2.6.3+
Fix from $1,950 2026-03-18
Roxy Wi HIGH 7.5
CVE-2026-22265

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in th…

Fix: 8.2.8.2+
Fix from $1,950 2026-01-15
Roxy Wi HIGH 8.8
CVE-2024-43804

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated…

No fix yet
Fix from $1,950 2024-08-29
Roxy Wi MEDIUM 6.5
CVE-2023-29004

hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerability was found in the current…

Fix: after 6.3.9.0
Fix from $1,600 2023-04-17
Roxy Wi MEDIUM 5.3
CVE-2023-25804

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulne…

Fix: 6.3.5.0+
Fix from $1,600 2023-03-15
Roxy Wi HIGH 7.5
CVE-2023-25803

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerab…

Fix: 6.3.5.0+
Fix from $1,950 2023-03-13
Roxy Wi HIGH 7.5
CVE-2023-25802

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../…

Fix: 6.3.6.0+
Fix from $1,950 2023-03-13
Roxy Wi CRITICAL 9.8
CVE-2022-31161EPSS 27%

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-15
Roxy Wi CRITICAL 9.8
CVE-2022-31137EPSS 90%

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code executi…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-08
Roxy Wi CRITICAL 9.8
CVE-2022-31125EPSS 20%

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-06
Roxy Wi CRITICAL 9.8
CVE-2022-31126EPSS 50%

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…

Fix: 6.1.1.0+
Fix from $2,300 2022-07-06
Roxy Wi CRITICAL 9.8
CVE-2021-38167

Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.

Fix: after 5.2.2.0
Fix from $2,300 2021-08-07
Roxy Wi HIGH 8.8
CVE-2021-38168

Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.

Fix: after 5.2.2.0
Fix from $1,950 2021-08-07
Roxy Wi HIGH 8.8
CVE-2021-38169

Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.

Fix: after 5.2.2.0
Fix from $1,950 2021-08-07