Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.68%—Nginx Cache Purge PreloadAI22/7/202517/6/2026
The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER'] parameter passed from the…
ModificadaAlta (7.7)0.81%—Openresty Lua-nginx-module22/4/202517/6/2026
An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.
AplazadaAlta (8.8)30%💥 ExploitKubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the…
AplazadaMedia (4.8)3.3%—Kubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with…
AplazadaCrítica (9.8)99%💥 ExploitKubernetes Ingress NginxAI25/3/202517/6/2026
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default…
AplazadaAlta (8.8)82%💥 ExploitKubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure…
AplazadaAlta (8.8)33%💥 ExploitKubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to…
AnalizadaMedia (6.9)0.59%—F5 Nginx Unit4/3/202517/6/2026
In NGINX Unit before version 1.34.2 with the Java Language Module in use, undisclosed requests can lead to an infinite loop and cause an increase in CPU resource utilization. This vulnerability allows a remote attacker to cause a degradation that can lead to a limited denial-of-service (DoS). There is no control plane…
AnalizadaMedia (5.3)2.8%💥 PoCF5 NginxF5 Nginx PlusDebian Linux5/2/202517/6/2026
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets…
AplazadaMedia (4.3)0.41%—Ekaterir Cache Sniper FOR NginxAI16/1/202517/6/2026
Missing Authorization vulnerability in ekaterir Cache Sniper for Nginx snipe-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cache Sniper for Nginx: from n/a through <= 1.0.4.2.
AplazadaMedia (4.3)0.35%—Juni Hestia Nginx CacheAI2/1/202517/6/2026
Missing Authorization vulnerability in Juni Hestia Nginx Cache hestia-nginx-cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through <= 2.4.0.
AnalizadaMedia (5.1)0.35%—F5 Nginx API Connectivity ManagerF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Openid Connect6/11/202417/6/2026
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session…
AnalizadaAlta (8.9)28%💥 PoCNginxui Nginx UI21/10/202417/6/2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.
AnalizadaMedia (5.5)0.64%—Nginxui Nginx UI21/10/202417/6/2026
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue.
AnalizadaAlta (7.7)0.60%—Nginxui Nginx UI21/10/202417/6/2026
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26…
AnalizadaMedia (6.3)1.3%—Jc21 Nginx Proxy Manager27/9/202417/6/2026
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5.
AnalizadaCrítica (9.8)3.1%💥 PoCJc21 Nginx Proxy Manager27/9/202417/6/2026
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
AnalizadaMedia (6.9)0.47%—F5 Nginx AgentF5 Nginx Instance Manager22/8/202417/6/2026
NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
AplazadaAlta (8.8)27%💥 PoCKubernetes Ingress NginxAI16/8/202417/6/2026
A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that…
ModificadaMedia (5.7)0.32%—F5 Nginx Open SourceF5 Nginx Plus14/8/202417/6/2026
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in…
AnalizadaAlta (8.7)0.63%—F5 Nginx Plus14/8/202417/6/2026
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.8)0.88%—Jc21 Nginx Proxy Manager4/7/202417/6/2026
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.
AnalizadaMedia (5.3)0.93%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
AnalizadaMedia (5.3)0.87%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
AnalizadaMedia (6.5)0.86%—F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora29/5/202417/6/2026
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact.
Orbitaley — Vulnerabilidades