jc21 kayıtları
jc21 üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-1259 Improper Restriction of Security Token Assignment1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2023-23596İstismar yok | jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection.jc21 · nginx proxy manager · CWE-78 | Yüksek8,8 | — | %15,2 | 20 Oca 2023 |
40Planlayın | CVE-2024-46256Kavram kanıtı | A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certijc21 · nginx proxy manager · CWE-77 | Kritik9,8 | — | %3,1 | 27 Eyl 2024 |
39İzleyin | CVE-2023-27224İstismar yok | An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.jc21 · nginx proxy manager · CWE-77 | Kritik9,8 | — | %1,2 | 22 Mar 2023 |
35İzleyin | CVE-2024-39935İstismar yok | jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificatjc21 · nginx proxy manager · CWE-78 | Yüksek8,8 | — | %0,9 | 4 Tem 2024 |
25İzleyin | CVE-2024-46257İstismar yok | A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote jc21 · nginx proxy manager · CWE-89 | Orta6,3 | — | %1,3 | 27 Eyl 2024 |
22İzleyin | CVE-2019-15517İstismar yok | jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.jc21 · nginx proxy manager · CWE-22 | Orta5,5 | — | %0,7 | 23 Ağu 2019 |
21İzleyin | CVE-2025-50579İstismar yok | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due tojc21 · nginx proxy manager · CWE-1259 | Orta5,3 | — | %0,4 | 19 Ağu 2025 |
- CVE-2023-2359640Planlayın
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection.
YüksekCVSS 8,8İstismar yokEPSS %15jc21 · nginx proxy manager20 Oca 2023
- CVE-2024-4625640Planlayın
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certi
KritikCVSS 9,8Kavram kanıtıEPSS %3jc21 · nginx proxy manager27 Eyl 2024
- CVE-2023-2722439İzleyin
An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.
KritikCVSS 9,8İstismar yokEPSS %1jc21 · nginx proxy manager22 Mar 2023
- CVE-2024-3993535İzleyin
jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificat
YüksekCVSS 8,8İstismar yokEPSS %1jc21 · nginx proxy manager4 Tem 2024
- CVE-2024-4625725İzleyin
A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote
OrtaCVSS 6,3İstismar yokEPSS %1jc21 · nginx proxy manager27 Eyl 2024
- CVE-2019-1551722İzleyin
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
OrtaCVSS 5,5İstismar yokEPSS %1jc21 · nginx proxy manager23 Ağu 2019
- CVE-2025-5057921İzleyin
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to
OrtaCVSS 5,3İstismar yokEPSS %0jc21 · nginx proxy manager19 Ağu 2025