Exposição de Nginx

Reverse proxies, Web servers
221
score de exposição
2.184.939
sites usam
0
em exploração
12
críticos
Análise Vexday

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 resultados
CVE-2024-24989HIGHNGINX HTTP/3 QUIC vulnerabilityEPSS 1.1%CVE-2024-23828HIGHNginx-UI authenticated RCE through injecting into the application config via CRLFEPSS 1.1%CVE-2020-5864In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by defEPSS 1.0%CVE-2026-27784HIGHNGINX ngx_http_mp4_module vulnerabilityEPSS 1.0%CVE-2020-5894On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out.EPSS 1.0%CVE-2020-5911In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL EPSS 1.0%CVE-2026-33029MEDIUMNginx UI: DoS via Negative Integer Input in Logrotate IntervalEPSS 0.9%CVE-2026-27651HIGHNGINX ngx_mail_auth_http_module vulnerabilityEPSS 0.9%CVE-2024-35200MEDIUMNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%CVE-2026-42946HIGHNGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerabilityEPSS 0.9%CVE-2026-40519HIGHNginx Proxy Manager Authenticated RCE via setupCertbotPlugins()EPSS 0.9%CVE-2026-32647HIGHNGINX ngx_http_mp4_module vulnerabilityEPSS 0.9%CVE-2024-3736MEDIUMcym1102 nginxWebUI upload unrestricted uploadEPSS 0.9%CVE-2024-24990HIGHNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%CVE-2024-3737MEDIUMcym1102 nginxWebUI addOver findCountByQuery path traversalEPSS 0.9%CVE-2020-8553MEDIUMKubernetes ingress-nginx Compromise of auth via subset/superset namespace namesEPSS 0.9%CVE-2026-8711CRITICALNGINX JavaScript vulnerabilityEPSS 0.9%CVE-2024-31079MEDIUMNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%CVE-2024-34161MEDIUMNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%CVE-2024-32760MEDIUMNGINX HTTP/3 QUIC vulnerabilityEPSS 0.9%