Exposição de Nginx

Reverse proxies, Web servers
221
score de exposição
2.184.939
sites usam
0
em exploração
12
críticos
Análise Vexday

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 resultados
CVE-2024-3740MEDIUMcym1102 nginxWebUI reload exec deserializationEPSS 0.8%CVE-2022-41741HIGHNGINX ngx_http_mp4_module vulnerability CVE-2022-41741EPSS 0.8%CVE-2026-42238CRITICALUnauthenticated Remote Code Execution via Backup Restore in nginx-uiEPSS 0.8%CVE-2021-23055On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller doesEPSS 0.7%CVE-2026-42934MEDIUMNGINX ngx_http_charset_module vulnerabilityEPSS 0.7%CVE-2022-35241MEDIUMNGINX Instance Manager vulnerability CVE-2022-35241EPSS 0.7%CVE-2026-60005HIGHNGINX ngx_http_slice_module vulnerabilityEPSS 0.7%CVE-2024-23827CRITICALNginx-UI arbitrary file write through the Import Certificate featureEPSS 0.7%CVE-2021-25748HIGHIngress-nginx `path` sanitization can be bypassed with newline characterEPSS 0.7%CVE-2026-40701MEDIUMNGINX ngx_http_ssl_module vulnerabilityEPSS 0.7%CVE-2026-48142MEDIUMNGINX ngx_http_charset_module vulnerabilityEPSS 0.7%CVE-2025-6213HIGHNginx Cache Purge Preload <= 2.1.1 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.7%CVE-2022-30535MEDIUMNGINX Ingress Controller vulnerability CVE-2022-30535EPSS 0.7%CVE-2025-62126MEDIUMWordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerabilityEPSS 0.7%CVE-2024-49367MEDIUMNginx UI's log path can be controlledEPSS 0.6%CVE-2024-39792HIGHNGINX Plus MQTT vulnerabilityEPSS 0.6%CVE-2024-49366HIGHNginx UI's json field can construct a directory traversal payload, causing arbitrary files to be writtenEPSS 0.6%CVE-2024-22196HIGHAuthenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)EPSS 0.6%CVE-2025-1695MEDIUMNGINX Unit Java VulnerabilityEPSS 0.6%CVE-2026-11311HIGHNGINX Gateway Fabric vulnerabilityEPSS 0.6%