Exposición de Nginx

Reverse proxies, Web servers
217
score de exposición
2.184.939
sitios usan
0
en explotación
12
críticos
Análisis Vexday

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 resultados
CVE-2021-23018Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocEPSS 0.5%CVE-2026-33028HIGHNginx UI: Race Condition Leads to Persistent Data Corruption and Service CollapseEPSS 0.5%CVE-2022-23008On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisEPSS 0.5%CVE-2023-28656HIGHNGINX Management Suite vulnerabilityEPSS 0.5%CVE-2024-3738HIGHcym1102 nginxWebUI saveCmd handlePath certificate validationEPSS 0.5%CVE-2026-24512HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2026-50107HIGHNGINX Gateway Fabric vulnerabilityEPSS 0.5%CVE-2026-1580HIGHingress-nginx auth-method nginx configuration injectionEPSS 0.5%CVE-2024-7634MEDIUMNGINX Agent VulnerabilityEPSS 0.5%CVE-2025-15566HIGHingress-nginx auth-proxy-set-headers nginx configuration injectionEPSS 0.5%CVE-2021-23050On BIG-IP Advanced WAF and BIG-IP ASM version 16.0.x before 16.0.1.2 and 15.1.x before 15.1.3 and NGINX App Protect on all versions before 3EPSS 0.5%CVE-2026-24514MEDIUMingress-nginx Admission Controller denial of serviceEPSS 0.5%CVE-2020-5900In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX ControlleEPSS 0.5%CVE-2026-56434HIGHNGINX ngx_http_ssi_module vulnerabilityEPSS 0.4%CVE-2025-23776MEDIUMWordPress Cache Sniper for Nginx plugin <= 1.0.4.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2020-5867In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packageEPSS 0.4%CVE-2020-5909In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the aEPSS 0.4%CVE-2026-33027MEDIUMNginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration DirectoryEPSS 0.4%CVE-2025-53859MEDIUMNGINX ngx_mail_smtp_module vulnerabilityEPSS 0.4%CVE-2020-5865In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, mEPSS 0.4%