Exposición de Nginx

Reverse proxies, Web servers
217
score de exposición
2.184.939
sitios usan
0
en explotación
12
críticos
Análisis Vexday

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 resultados
CVE-2025-14727HIGHNGINX Ingress Controller vulnerabilityEPSS 0.4%CVE-2026-40460MEDIUMNGINX ngx_quic_module vulnerabilityEPSS 0.4%CVE-2025-58474MEDIUMBIG-IP Advanced WAF and ASM and NGINX App Protect DNS lookup vulnerabilityEPSS 0.4%CVE-2024-56236MEDIUMWordPress Hestia Nginx Cache plugin <= 2.4.0 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.4%CVE-2026-42221HIGHnginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin ClaimEPSS 0.3%CVE-2026-42926MEDIUMNGINX ngx_http_proxy_v2_module vulnerabilityEPSS 0.3%CVE-2020-5866In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses EPSS 0.3%CVE-2026-1642HIGHNGINX vulnerabilityEPSS 0.3%CVE-2026-42222HIGHnginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeoverEPSS 0.3%CVE-2024-10318MEDIUMNGINX OpenID Connect VulnerabilityEPSS 0.3%CVE-2026-33026CRITICALnginx-ui Backup Restore Allows Tampering with Encrypted BackupsEPSS 0.3%CVE-2022-27495MEDIUMOn all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: SoftwareEPSS 0.3%CVE-2024-7347MEDIUMNGINX MP4 module vulnerabilityEPSS 0.3%CVE-2026-44015HIGHNginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal ServicesEPSS 0.3%CVE-2020-5895On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or uEPSS 0.3%CVE-2026-24513LOWingress-nginx auth-url protection bypassEPSS 0.3%CVE-2026-42220MEDIUMnginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollbackEPSS 0.3%CVE-2026-42223MEDIUMnginx-ui: Settings API Exposes Protected SecretsEPSS 0.3%CVE-2026-55723HIGHNGINX Ingress Controller vulnerabilityEPSS 0.3%CVE-2026-32682HIGHNGINX Gateway Fabric vulnerabilityEPSS 0.3%