Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.89% | — | F5 Nginx Open SourceF5 Nginx PlusFedoraproject Fedora | 29/5/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility… | |
| Analizada | Crítica (9.8) | 0.81% | — | Cym1102 Nginxwebui | 13/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file /adminPage/conf/reload. The manipulation of the argument nginxExe leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Crítica (9.8) | 2.9% | — | Cym1102 Nginxwebui | 13/4/2024 | 17/6/2026 | A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of the argument file leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Crítica (9.8) | 0.52% | — | Cym1102 Nginxwebui | 13/4/2024 | 17/6/2026 | A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation of the argument nginxPath leads to improper certificate validation. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.90% | — | Cym1102 Nginxwebui | 13/4/2024 | 17/6/2026 | A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of the file /adminPage/www/addOver. The manipulation of the argument dir leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.5) | 0.92% | — | Cym1102 Nginxwebui | 13/4/2024 | 17/6/2026 | A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adminPage/main/upload. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (7.5) | 0.91% | — | F5 Nginx Open SourceF5 Nginx Plus | 14/2/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3… | |
| Modificada | Alta (7.5) | 1.1% | — | F5 Nginx Open SourceF5 Nginx Plus | 14/2/2024 | 17/6/2026 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3… | |
| Modificada | Alta (8.8) | 1.1% | — | Nginxui Nginx UI | 29/1/2024 | 17/6/2026 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been… | |
| Modificada | Crítica (9.8) | 0.70% | — | Nginxui Nginx UI | 29/1/2024 | 17/6/2026 | Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a… | |
| Modificada | Alta (8.8) | 4.1% | 💥 PoC | Nginxui Nginx UI | 11/1/2024 | 17/6/2026 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow… | |
| Modificada | Media (6.5) | 0.58% | — | Nginxui Nginx UI | 11/1/2024 | 17/6/2026 | Nginx-UI is an online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"` and `"id"` values are used as default values if the query parameters are not set. Thus, the `order`… | |
| Modificada | Alta (8.8) | 1.5% | — | Nginxui Nginx UI | 11/1/2024 | 17/6/2026 | Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `Nginx Error Log Path`. However, the API also exposes `test_config_cmd`, `reload_cmd`… | |
| Modificada | Alta (8.8) | 57% | 💥 PoC | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Ingress nginx annotation injection causes arbitrary command execution. | |
| Modificada | Media (6.5) | 1.6% | — | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 0.69% | — | Kubernetes Ingress-nginx | 24/5/2023 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the… | |
| Analizada | Alta (7.1) | 0.17% | — | F5 Nginx API Connectivity ManagerF5 Nginx Instance ManagerF5 Nginx Security Monitoring | 3/5/2023 | 17/6/2026 | NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.1) | 0.53% | — | Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+1 | 3/5/2023 | 17/6/2026 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Media (5.5) | 0.22% | — | F5 Nginx AgentF5 Nginx Instance Manager | 29/3/2023 | 17/6/2026 | Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information into a log file. An authenticated attacker with local access to read agent log files may gain access to private keys. This issue is only exposed when the non-default trace… | |
| Modificada | Crítica (9.8) | 1.2% | — | Jc21 Nginx Proxy Manager | 22/3/2023 | 17/6/2026 | An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | |
| Modificada | Alta (8.8) | 15% | — | Jc21 Nginx Proxy Manager | 20/1/2023 | 17/6/2026 | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to… | |
| Modificada | Alta (7) | 0.22% | — | F5 Nginx Ingress ControllerF5 Nginx Plus | 19/10/2022 | 17/6/2026 | NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file. The issue affects only NGINX Plus when the hls directive… | |
| Modificada | Alta (7.1) | 1.1% | — | F5 NginxF5 Nginx Ingress ControllerFedoraproject FedoraDebian Linux | 19/10/2022 | 17/6/2026 | NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker… |