Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.68% | — | Nginx Cache Purge PreloadAI | 22/7/2025 | 17/6/2026 | The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER'] parameter passed from the… | |
| Modificada | Alta (7.7) | 0.81% | — | Openresty Lua-nginx-module | 22/4/2025 | 17/6/2026 | An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request. | |
| Aplazada | Alta (8.8) | 30% | 💥 Exploit | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the… | |
| Aplazada | Media (4.8) | 3.3% | — | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with… | |
| Aplazada | Crítica (9.8) | 99% | 💥 Exploit | Kubernetes Ingress NginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default… | |
| Aplazada | Alta (8.8) | 82% | 💥 Exploit | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure… | |
| Aplazada | Alta (8.8) | 33% | 💥 Exploit | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to… | |
| Analizada | Media (6.9) | 0.59% | — | F5 Nginx Unit | 4/3/2025 | 17/6/2026 | In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS). There is no control plane… | |
| Analizada | Media (5.3) | 2.8% | 💥 PoC | F5 NginxF5 Nginx PlusDebian Linux | 5/2/2025 | 17/6/2026 | When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets… | |
| Aplazada | Media (4.3) | 0.41% | — | Ekaterir Cache Sniper FOR NginxAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in ekaterir Cache Sniper for Nginx snipe-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through <= 1.0.4.2. | |
| Aplazada | Media (4.3) | 0.35% | — | Juni Hestia Nginx CacheAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Juni Hestia Nginx Cache hestia-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through <= 2.4.0. | |
| Analizada | Media (5.1) | 0.35% | — | F5 Nginx API Connectivity ManagerF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Openid Connect | 6/11/2024 | 17/6/2026 | A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session… | |
| Analizada | Alta (8.9) | 28% | 💥 PoC | Nginxui Nginx UI | 21/10/2024 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue. | |
| Analizada | Media (5.5) | 0.64% | — | Nginxui Nginx UI | 21/10/2024 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue. | |
| Analizada | Alta (7.7) | 0.60% | — | Nginxui Nginx UI | 21/10/2024 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26… | |
| Analizada | Media (6.3) | 1.3% | — | Jc21 Nginx Proxy Manager | 27/9/2024 | 17/6/2026 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5. | |
| Analizada | Crítica (9.8) | 3.1% | 💥 PoC | Jc21 Nginx Proxy Manager | 27/9/2024 | 17/6/2026 | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. | |
| Analizada | Media (6.9) | 0.47% | — | F5 Nginx AgentF5 Nginx Instance Manager | 22/8/2024 | 17/6/2026 | NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory. | |
| Aplazada | Alta (8.8) | 27% | 💥 PoC | Kubernetes Ingress NginxAI | 16/8/2024 | 17/6/2026 | A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that… | |
| Modificada | Media (5.7) | 0.32% | — | F5 Nginx Open SourceF5 Nginx Plus | 14/8/2024 | 17/6/2026 | NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in… | |
| Analizada | Alta (8.7) | 0.63% | — | F5 Nginx Plus | 14/8/2024 | 17/6/2026 | When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.8) | 0.88% | — | Jc21 Nginx Proxy Manager | 4/7/2024 | 17/6/2026 | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5. | |
| Analizada | Media (5.3) | 0.93% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. | |
| Analizada | Media (5.3) | 0.87% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory. | |
| Analizada | Media (6.5) | 0.86% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. |