roxy-wi records
20 published records for vendor roxy-wi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 5%
- Pre-auth RCE
- 5
- With a fix record
- 15%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-287 Improper Authentication2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2022-31137Weaponized | Unauthenticated Remote Code Execution in Roxy-WIroxy-wi · roxy-wi · CWE-78 | Critical9.8 | — | 90.6% | Jul 8, 2022 |
55Plan | CVE-2022-31126Proof of concept | Unauthenticated Remote Code Execution in Roxy-wiroxy-wi · roxy-wi · CWE-74 | Critical9.8 | — | 52.6% | Jul 6, 2022 |
48Plan | CVE-2022-31161Proof of concept | Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Uploadroxy-wi · roxy-wi · CWE-77 | Critical9.8 | — | 28.4% | Jul 15, 2022 |
45Plan | CVE-2022-31125Proof of concept | Authentication Bypass in Roxy-wiroxy-wi · roxy-wi · CWE-287 | Critical9.8 | — | 20.3% | Jul 6, 2022 |
39Monitor | CVE-2021-38167No exploit | Roxy-WI through 5.2.2.0 allows SQL Injection via check_login.roxy-wi · roxy-wi · CWE-89 | Critical9.8 | — | 1.3% | Aug 7, 2021 |
36Monitor | CVE-2026-27811No exploit | Roxy-WI has a Command Injection via diff parameter in config comparison allows authenticated RCEroxy-wi · roxy-wi · CWE-77 | High8.8 | — | 3.0% | Mar 17, 2026 |
36Monitor | CVE-2024-43804No exploit | OS Command Injection via Port Scan Functionality in Roxy-WIroxy-wi · roxy-wi · CWE-78 | High8.8 | — | 2.6% | Aug 29, 2024 |
35Monitor | CVE-2021-38169No exploit | Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.roxy-wi · roxy-wi · CWE-77 | High8.8 | — | 1.5% | Aug 7, 2021 |
35Monitor | CVE-2026-33076No exploit | Roxy-WI vulnerable to path traversal and arbitrary file writingroxy-wi · roxy-wi · CWE-22 | High8.9 | — | 1.0% | Apr 23, 2026 |
35Monitor | CVE-2021-38168No exploit | Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.roxy-wi · roxy-wi · CWE-89 | High8.8 | — | 0.9% | Aug 7, 2021 |
35Monitor | CVE-2026-33078No exploit | Roxy-WI has SQL Injection in haproxy_section_save Endpoint via Unsanitized server_ip Parameterroxy-wi · roxy-wi · CWE-89 | High8.9 | — | 0.5% | Apr 23, 2026 |
31Monitor | CVE-2026-22265No exploit | Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticated RCEroxy-wi · roxy-wi · CWE-78 | High7.5 | — | 2.3% | Jan 15, 2026 |
30Monitor | CVE-2023-25803No exploit | Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers.roxy-wi · roxy-wi · CWE-22 | High7.5 | — | 1.2% | Mar 13, 2023 |
30Monitor | CVE-2023-25802No exploit | Roxy-WI has Path Traversal vulnerabilityroxy-wi · roxy-wi · CWE-22 | High7.5 | — | 1.0% | Mar 13, 2023 |
30Monitor | CVE-2026-33432No exploit | Roxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication Bypassroxy-wi · roxy-wi · CWE-287 | High7.7 | — | 0.6% | Apr 20, 2026 |
30Monitor | CVE-2026-33077No exploit | Roxy-WI has an arbitrary file read vulnerabilityroxy-wi · roxy-wi · CWE-22 | High7.7 | — | 0.5% | Apr 23, 2026 |
29Monitor | CVE-2026-33208No exploit | Roxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config Endpointroxy-wi · roxy-wi · CWE-78 | High7.4 | — | 0.9% | Apr 23, 2026 |
26Monitor | CVE-2023-29004No exploit | Path Traversal Vulnerability in hap-wi/roxy-wiroxy-wi · roxy-wi · CWE-22 | Medium6.5 | — | 0.9% | Apr 17, 2023 |
22Monitor | CVE-2026-33431No exploit | Roxy-WI Vulnerable to Authenticated Arbitrary File Read via Path Traversal in Config Version Viewerroxy-wi · roxy-wi · CWE-24 | Medium5.7 | — | 0.5% | Apr 20, 2026 |
21Monitor | CVE-2023-25804No exploit | Roxy-WI vulnerable to Limited Path Traversal in name parameterroxy-wi · roxy-wi · CWE-22 | Medium5.3 | — | 0.8% | Mar 15, 2023 |
- CVE-2022-3113766This week
Unauthenticated Remote Code Execution in Roxy-WI
CriticalCVSS 9.8WeaponizedEPSS 91%roxy-wi · roxy-wiJul 8, 2022
- CVE-2022-3112655Plan
Unauthenticated Remote Code Execution in Roxy-wi
CriticalCVSS 9.8Proof of conceptEPSS 53%roxy-wi · roxy-wiJul 6, 2022
- CVE-2022-3116148Plan
Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload
CriticalCVSS 9.8Proof of conceptEPSS 28%roxy-wi · roxy-wiJul 15, 2022
- CVE-2022-3112545Plan
Authentication Bypass in Roxy-wi
CriticalCVSS 9.8Proof of conceptEPSS 20%roxy-wi · roxy-wiJul 6, 2022
- CVE-2021-3816739Monitor
Roxy-WI through 5.2.2.0 allows SQL Injection via check_login.
CriticalCVSS 9.8No exploitEPSS 1%roxy-wi · roxy-wiAug 7, 2021
- CVE-2026-2781136Monitor
Roxy-WI has a Command Injection via diff parameter in config comparison allows authenticated RCE
HighCVSS 8.8No exploitEPSS 3%roxy-wi · roxy-wiMar 17, 2026
- CVE-2024-4380436Monitor
OS Command Injection via Port Scan Functionality in Roxy-WI
HighCVSS 8.8No exploitEPSS 3%roxy-wi · roxy-wiAug 29, 2024
- CVE-2021-3816935Monitor
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
HighCVSS 8.8No exploitEPSS 2%roxy-wi · roxy-wiAug 7, 2021
- CVE-2026-3307635Monitor
Roxy-WI vulnerable to path traversal and arbitrary file writing
HighCVSS 8.9No exploitEPSS 1%roxy-wi · roxy-wiApr 23, 2026
- CVE-2021-3816835Monitor
Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.
HighCVSS 8.8No exploitEPSS 1%roxy-wi · roxy-wiAug 7, 2021
- CVE-2026-3307835Monitor
Roxy-WI has SQL Injection in haproxy_section_save Endpoint via Unsanitized server_ip Parameter
HighCVSS 8.9No exploitEPSS 1%roxy-wi · roxy-wiApr 23, 2026
- CVE-2026-2226531Monitor
Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticated RCE
HighCVSS 7.5No exploitEPSS 2%roxy-wi · roxy-wiJan 15, 2026
- CVE-2023-2580330Monitor
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers.
HighCVSS 7.5No exploitEPSS 1%roxy-wi · roxy-wiMar 13, 2023
- CVE-2023-2580230Monitor
Roxy-WI has Path Traversal vulnerability
HighCVSS 7.5No exploitEPSS 1%roxy-wi · roxy-wiMar 13, 2023
- CVE-2026-3343230Monitor
Roxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication Bypass
HighCVSS 7.7No exploitEPSS 1%roxy-wi · roxy-wiApr 20, 2026
- CVE-2026-3307730Monitor
Roxy-WI has an arbitrary file read vulnerability
HighCVSS 7.7No exploitEPSS 1%roxy-wi · roxy-wiApr 23, 2026
- CVE-2026-3320829Monitor
Roxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config Endpoint
HighCVSS 7.4No exploitEPSS 1%roxy-wi · roxy-wiApr 23, 2026
- CVE-2023-2900426Monitor
Path Traversal Vulnerability in hap-wi/roxy-wi
MediumCVSS 6.5No exploitEPSS 1%roxy-wi · roxy-wiApr 17, 2023
- CVE-2026-3343122Monitor
Roxy-WI Vulnerable to Authenticated Arbitrary File Read via Path Traversal in Config Version Viewer
MediumCVSS 5.7No exploitEPSS 0%roxy-wi · roxy-wiApr 20, 2026
- CVE-2023-2580421Monitor
Roxy-WI vulnerable to Limited Path Traversal in name parameter
MediumCVSS 5.3No exploitEPSS 1%roxy-wi · roxy-wiMar 15, 2023