Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26567
Total
1967
Critical
8010
High
8270
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45567 | HIGH | 8.3 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via … | Jun 10, 2026 |
| CVE-2026-45566 | MEDIUM | 6.1 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the login flow allow-lists next URLs by … | Jun 10, 2026 |
| CVE-2026-45565 | HIGH | 8.1 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is the centralised Pydantic validator … | Jun 10, 2026 |
| CVE-2026-25700 | HIGH | 7.2 | Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after … | Jun 10, 2026 |
| CVE-2026-9045 | HIGH | 7.8 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local … | Jun 10, 2026 |
| CVE-2026-8637 | HIGH | 7.8 | A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code … | Jun 10, 2026 |
| CVE-2026-8335 | UNKNOWN | — | A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute arbitrary "SELECT" SQL queries and retrieve database data, as the endpoint … | Jun 10, 2026 |
| CVE-2026-7516 | MEDIUM | 4.3 | A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the … | Jun 10, 2026 |
| CVE-2026-6090 | HIGH | 7.0 | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated … | Jun 10, 2026 |
| CVE-2026-53689 | HIGH | 7.1 | libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This … | Jun 10, 2026 |
| CVE-2026-53476 | CRITICAL | 9.6 | A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting … | Jun 10, 2026 |
| CVE-2026-53475 | CRITICAL | 9.3 | A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) … | Jun 10, 2026 |
| CVE-2026-53474 | CRITICAL | 9.6 | A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper … | Jun 10, 2026 |
| CVE-2026-53473 | HIGH | 7.3 | A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational … | Jun 10, 2026 |
| CVE-2026-53471 | CRITICAL | 9.6 | A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate … | Jun 10, 2026 |
| CVE-2026-53470 | CRITICAL | 9.6 | A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker … | Jun 10, 2026 |
| CVE-2026-53469 | CRITICAL | 9.1 | A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper … | Jun 10, 2026 |
| CVE-2026-45564 | HIGH | 8.8 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /config/versions/<service>/<server_ip>/<configver>/save interpolates the URL-path configver parameter … | Jun 10, 2026 |
| CVE-2026-45563 | MEDIUM | 4.3 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter … | Jun 10, 2026 |
| CVE-2026-45561 | MEDIUM | 6.5 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the /smon/agent/{version,uptime,status,checks}/<server_ip> family of routes takes the … | Jun 10, 2026 |
| CVE-2026-45560 | MEDIUM | 6.1 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wrap_line (app/modules/common/common.py:181-186) and highlight_word (app/modules/common/common.py:188-192) build raw … | Jun 10, 2026 |
| CVE-2026-45559 | MEDIUM | 4.9 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get_ldap_email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter … | Jun 10, 2026 |
| CVE-2026-45558 | CRITICAL | 9.9 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the HAProxy section-save endpoints (POST /api/service/haproxy/<server_id>/section/<section_type> and … | Jun 10, 2026 |
| CVE-2026-45556 | CRITICAL | 9.9 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, POST /waf/<service>/<server_ip>/rule/<rule_id>/save accepts a config_file_name form field … | Jun 10, 2026 |
| CVE-2026-45552 | CRITICAL | 9.9 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → … | Jun 10, 2026 |