Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.59% | — | Nginxui Nginx UIUozi Cosy | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration… | |
| Analizada | Media (6.9) | 0.55% | — | Nginxui Nginx UI | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base… | |
| Modificada | Alta (8.5) | 0.34% | — | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 15/7/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source… | |
| Analizada | Media (5.3) | 0.15% | 💥 PoC | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 17/6/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling of revoked certificates when configured with the ssl_verify_client on and ssl_ocsp on directives, allowing the TLS handshake to succeed even after an OCSP check identifies the certificate as revoked.… | |
| Analizada | Media (6.3) | 0.26% | — | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 17/6/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation. Note: Software… | |
| Modificada | Alta (8.5) | 1.0% | — | F5 Nginx Open Source | 24/3/2026 | 15/7/2026 | The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the… | |
| Modificada | Alta (8.8) | 25% | 💥 PoC | F5 Nginx PlusF5 Nginx Open Source | 24/3/2026 | 15/7/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the… | |
| Modificada | Alta (8.7) | 0.94% | — | F5 Nginx Open SourceF5 Nginx Plus | 24/3/2026 | 15/7/2026 | When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header.… | |
| Analizada | Alta (8.8) | 0.60% | 💥 PoC | Kubernetes Nginx Ingress Controller | 19/3/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default… | |
| Analizada | Alta (8.8) | 0.74% | 💥 PoC | Kubernetes Ingress-nginx | 9/3/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller.… | |
| Analizada | Crítica (9.8) | 1.0% | 💥 Exploit | Nginxui Nginx UI | 5/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system… | |
| Analizada | Baja (2) | 0.30% | — | Cym1102 Nginxwebui | 8/2/2026 | 17/6/2026 | A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipulation of the argument nginxDir leads to cross site scripting. The attack can be executed remotely. The exploit is… | |
| Aplazada | Alta (8.8) | 0.53% | — | Kubernetes Ingress-nginxAI | 6/2/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the… | |
| Analizada | Alta (8.2) | 0.39% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+1 | 4/2/2026 | 17/6/2026 | A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response… | |
| Aplazada | Media (6.5) | 0.52% | 💥 PoC | Ingress NginxAI | 3/2/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed… | |
| Aplazada | Baja (3.1) | 0.34% | — | Ingress NginxAI | 3/2/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if… | |
| Aplazada | Alta (8.8) | 0.56% | — | Ingress NginxAI | 3/2/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default… | |
| Aplazada | Alta (8.8) | 0.54% | — | Ingress NginxAI | 3/2/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note… | |
| Aplazada | Media (5.3) | 0.71% | 💥 Exploit | Razvan Stanga Varnish Nginx Proxy CachingAI | 31/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Retrieve Embedded Sensitive Data.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3. | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Nginx Ingress Controller | 17/12/2025 | 17/6/2026 | A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Media (4.3) | 0.20% | — | Nginxcacheoptimizer Nginx Cache OptimizerAI | 24/10/2025 | 17/6/2026 | The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nginxcacheoptimizer-blacklist-update' AJAX action in all versions up to, and including, 1.1. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (5.9) | 0.22% | — | Razvan Stanga Varnish Nginx Proxy CachingAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Stored XSS.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3. | |
| Aplazada | Media (6.5) | 0.24% | — | Nginx DefenderAI | 19/8/2025 | 17/6/2026 | nginx-defender is a high-performance, enterprise-grade Web Application Firewall (WAF) and threat detection system engineered for modern web infrastructure. This is a configuration vulnerability affecting nginx-defender deployments. Example configuration files config.yaml and docker-compose.yml contain default… | |
| Analizada | Media (5.3) | 0.38% | — | Jc21 Nginx Proxy Manager | 19/8/2025 | 17/6/2026 | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote… | |
| Modificada | Media (6.3) | 0.41% | — | F5 Nginx PlusF5 Nginx Open Source | 13/8/2025 | 17/6/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_smtp_module that might allow an unauthenticated attacker to over-read NGINX SMTP authentication process memory; as a result, the server side may leak arbitrary bytes sent in a request to the authentication server. This issue happens during the NGINX… |