Exposição de Nginx

Reverse proxies, Web servers
221
score de exposição
2.184.939
sites usam
0
em exploração
12
críticos
Análise Vexday

O histórico de vulnerabilidades do Nginx reúne 132 CVEs catalogadas, com 11 classificadas como críticas e 29 surgidas apenas nos últimos 90 dias, indicando um ritmo recente de descobertas que merece acompanhamento contínuo. Embora nenhuma CVE esteja atualmente confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo —, o score EPSS mais alto observado atinge 0,99098, sugerindo que ao menos uma vulnerabilidade tem probabilidade muito elevada de exploração. A CVE mais perigosa em evidência hoje é CVE-2025-1974, com EPSS de 0,991, o que a coloca em patamar de risco imediato e exige priorização nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que tende a manifestar-se em superfícies de ataque amplas, especialmente em componentes voltados ao processamento de requisições externas.

CVEs

139 resultados
CVE-2026-52865HIGHNGINX Ingress Controller vulnerabilityEPSS 0.3%CVE-2026-33030HIGHNginx UI: Unencrypted Storage of DNS API Tokens and ACME Private KeysEPSS 0.3%CVE-2026-33031HIGHNginx-UI: Disabled users retain full API access through previously issued bearer tokensEPSS 0.3%CVE-2026-60065MEDIUMNGINX Plus ngx_stream_mqtt_filter_module vulnerabilityEPSS 0.3%CVE-2026-28753MEDIUMNGINX ngx_mail_proxy_module vulnerabilityEPSS 0.3%CVE-2026-2145MEDIUMcym1102 nginxWebUI Web Management check cross site scriptingEPSS 0.3%CVE-2021-23020The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictaEPSS 0.3%CVE-2025-55740MEDIUMDefault Credentials in nginx-defender Configuration FilesEPSS 0.2%CVE-2021-23019The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included iEPSS 0.2%CVE-2021-23021The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission biEPSS 0.2%CVE-2025-48360MEDIUMWordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2022-41743HIGHNGINX ngx_http_hls_module vulnerability CVE-2022-41743EPSS 0.2%CVE-2023-1550MEDIUMNGINX Agent vulnerability CVE-2023-1550EPSS 0.2%CVE-2026-60062MEDIUMNGINX Agent VulnerabilityEPSS 0.2%CVE-2025-12014MEDIUMNGINX Cache Optimizer <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Dynamic Caching Exclusion UpdateEPSS 0.2%CVE-2020-5899In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text,EPSS 0.2%CVE-2026-34403MEDIUMNginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpointsEPSS 0.2%CVE-2023-28724HIGHNGINX Management Suite vulnerabilityEPSS 0.2%CVE-2026-28755MEDIUMNGINX ngx_stream_ssl_module vulnerabilityEPSS 0.1%