Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 0.39% | — | Nginxui Nginx UI | 12/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to… | |
| Analizada | Crítica (9) | 0.83% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted… | |
| Analizada | Media (6.5) | 0.41% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/settings.go:24-65) serializes all settings structs to JSON and returns them to authenticated users. Many sensitive fields are tagged with protected:"true" - however, this tag is only enforced… | |
| Analizada | Crítica (9.8) | 0.47% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available. | |
| Analizada | Crítica (9.8) | 1.6% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without authentication,… | |
| Analizada | Media (6.5) | 0.40% | — | Nginxui Nginx UI | 4/5/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/settings and retrieve sensitive configuration values, including node.secret. The same node.secret is accepted by AuthRequired() through the X-Node-Secret header (or node_secret query parameter),… | |
| Analizada | Media (5.5) | 0.22% | — | Nginxui Nginx UI | 20/4/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). Combined with the fact that authentication tokens are stored in… | |
| Analizada | Alta (8.6) | 0.39% | — | Nginxui Nginx UI | 20/4/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that user’s access, so an attacker who already stole… | |
| Analizada | Crítica (9.4) | 0.21% | — | Nginxui Nginx UI | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4. | |
| Modificada | Crítica (9.8) | 2.5% | — | Nginxui Nginx UI | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only… | |
| Analizada | Crítica (9.9) | 0.38% | — | Nginxui Nginx UI | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base Model struct lacks a user_id… | |
| Analizada | Media (6.9) | 0.48% | — | Nginxui Nginx UI | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative integer for the rotation interval, the backend enters an infinite loop… | |
| Analizada | Alta (7.1) | 0.59% | — | Nginxui Nginx UIUozi Cosy | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration… | |
| Analizada | Media (6.9) | 0.55% | — | Nginxui Nginx UI | 30/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx configuration directory and executes the operation on the base… | |
| Analizada | Crítica (9.8) | 1.0% | — | Nginxui Nginx UI | 5/3/2026 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system… | |
| Analizada | Alta (8.9) | 28% | — | Nginxui Nginx UI | 21/10/2024 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue. | |
| Analizada | Media (5.5) | 0.64% | — | Nginxui Nginx UI | 21/10/2024 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue. | |
| Analizada | Alta (7.7) | 0.60% | — | Nginxui Nginx UI | 21/10/2024 | 17/6/2026 | Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26… | |
| Modificada | Alta (8.8) | 1.1% | — | Nginxui Nginx UI | 29/1/2024 | 17/6/2026 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been… | |
| Modificada | Crítica (9.8) | 0.70% | — | Nginxui Nginx UI | 29/1/2024 | 17/6/2026 | Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a… | |
| Modificada | Alta (8.8) | 4.1% | — | Nginxui Nginx UI | 11/1/2024 | 17/6/2026 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow… | |
| Modificada | Media (6.5) | 0.58% | — | Nginxui Nginx UI | 11/1/2024 | 17/6/2026 | Nginx-UI is an online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"` and `"id"` values are used as default values if the query parameters are not set. Thus, the `order`… | |
| Modificada | Alta (8.8) | 1.5% | — | Nginxui Nginx UI | 11/1/2024 | 17/6/2026 | Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `Nginx Error Log Path`. However, the API also exposes `test_config_cmd`, `reload_cmd`… |