Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.79%💥 PoCF5 NginxF5 Nginx Ingress ControllerFedoraproject FedoraDebian Linux19/10/202217/6/2026
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or…
ModificadaAlta (7.5)1.4%—Nginx NJS18/8/202217/6/2026
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.
ModificadaMedia (6.5)0.74%—F5 Nginx Instance Manager4/8/202217/6/2026
In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (6.5)0.69%—F5 Nginx Ingress Controller4/8/202217/6/2026
In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (5.5)0.29%—Nginx NJS2/6/202217/6/2026
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_set_number at src/njs_value.h.
ModificadaMedia (5.5)0.38%—Nginx NJS2/6/202217/6/2026
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_array.c.
ModificadaMedia (5.5)0.38%—Nginx NJS2/6/202217/6/2026
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
ModificadaAlta (7.1)1.4%—Kubernetes Ingress-nginx6/5/202217/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has…
ModificadaAlta (8.1)1.2%—Kubernetes Ingress-nginx6/5/202217/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that…
ModificadaMedia (6.5)0.34%—F5 Nginx Service Mesh5/5/202217/6/2026
On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
ModificadaMedia (6.5)0.77%—F5 Nginx Ingress Controller21/4/202217/6/2026
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (4.8)71%—Nginxproxymanager Nginx Proxy Manager3/4/202217/6/2026
jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion.
ModificadaAlta (7.4)2.0%—F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+123/3/202217/6/2026
ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to…
ModificadaCrítica (9.8)3.1%—Nginx NJS14/2/202217/6/2026
njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.
ModificadaMedia (5.4)0.53%—F5 Nginx Controller API Management25/1/202217/6/2026
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have…
ModificadaAlta (7.5)3.2%💥 PoCOwasp ModsecurityTrustwave ModsecurityF5 Nginx Modsecurity WAFDebian Linux+27/12/202117/6/2026
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for…
ModificadaAlta (7.1)2.1%—Kubernetes Ingress-nginxNetapp Trident29/10/202117/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
ModificadaAlta (7.5)0.47%—F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security ManagerF5 Nginx APP Protect14/9/202117/6/2026
On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3.5.0, when a cross-site request forgery (CSRF)-enabled policy is configured on a virtual server, an undisclosed HTML response may cause the bd process to terminate. Note: Software…
ModificadaCrítica (9.8)3.3%—F5 NginxDebian Linux6/6/202117/6/2026
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
ModificadaMedia (5.5)0.23%—F5 Nginx Controller1/6/202117/6/2026
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.
ModificadaMedia (5.5)0.26%—F5 Nginx Controller1/6/202117/6/2026
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
ModificadaAlta (7.8)0.24%—F5 Nginx Controller1/6/202117/6/2026
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.
ModificadaAlta (7.7)53%💥 ExploitF5 NginxOpenrestyFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility+91/6/202117/6/2026
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
ModificadaAlta (7.4)0.54%—F5 Nginx Controller1/6/202117/6/2026
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.
ModificadaMedia (5.3)1.4%—Openresty Lua-nginx-module6/4/202117/6/2026
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.