Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 30/9/2026 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their… | |
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 29/9/2026 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session… | |
| Aplazada | Media (5.5) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 20/9/2026 | 22/9/2026 | A vulnerability was detected in NginxProxyManager nginx-proxy-manager up to 2.15.1. This impacts the function internalCertificate.validate of the file backend/internal/certificate.js of the component Validate Route. The manipulation results in missing authentication. The attack can be launched remotely. The exploit is… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Caddy Proxy ManagerAI | 17/9/2026 | 23/9/2026 | Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without… | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Nginx Proxy ManagerAI | 15/6/2026 | 17/6/2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request. | |
| Aplazada | Alta (7.7) | 1.7% | — | Nginxproxymanager Nginx Proxy ManagerAI | 8/6/2026 | 23/7/2026 | Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() function in backend/setup.js, allowing attackers with certificates:manage permission to execute arbitrary commands by storing a… | |
| Analizada | Media (5.3) | 0.38% | — | Jc21 Nginx Proxy Manager | 19/8/2025 | 17/6/2026 | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper validation of the Origin header. This misconfiguration enables attackers to intercept tokens using a simple browser script and exfiltrate them to a remote… | |
| Analizada | Media (6.3) | 1.3% | — | Jc21 Nginx Proxy Manager | 27/9/2024 | 17/6/2026 | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code execution via Add Let's Encrypt Certificate. NOTE: this is not part of any NGINX software shipped by F5. | |
| Analizada | Crítica (9.8) | 3.1% | — | Jc21 Nginx Proxy Manager | 27/9/2024 | 17/6/2026 | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. | |
| Analizada | Alta (8.8) | 0.88% | — | Jc21 Nginx Proxy Manager | 4/7/2024 | 17/6/2026 | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jc21 Nginx Proxy Manager | 22/3/2023 | 17/6/2026 | An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. | |
| Modificada | Alta (8.8) | 15% | — | Jc21 Nginx Proxy Manager | 20/1/2023 | 17/6/2026 | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted username and/or password input that is concatenated without any validation, and is directly passed to the exec command, potentially allowing an authenticated attacker to… | |
| Modificada | Media (4.8) | 71% | — | Nginxproxymanager Nginx Proxy Manager | 3/4/2022 | 17/6/2026 | jc21.com Nginx Proxy Manager before 2.9.17 allows XSS during item deletion. | |
| Modificada | Media (5.5) | 0.73% | — | Jc21 Nginx Proxy Manager | 23/8/2019 | 17/6/2026 | jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. |