İçeriğe atla
Noroxi

nginxui kayıtları

nginxui üreticisine ait 23 yayımlanmış kayıt.

Tüm kayıtlar

23 kayıt
  • CVE-2024-49368
    43Planlayın

    Unchecked logrotate settings lead to arbitrary command execution

    YüksekCVSS 8,9Kavram kanıtıEPSS %28

    nginxui · nginx ui21 Eki 2024

  • CVE-2026-33032
    40Planlayın

    Nginx UI: Unauthenticated MCP Endpoint Allows Remote Nginx Takeover

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    nginxui · nginx ui30 Mar 2026

  • CVE-2026-42221
    39İzleyin

    nginx-ui: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    nginxui · nginx ui4 May 2026

  • CVE-2026-27944
    39İzleyin

    Nginx UI: Unauthenticated Backup Download with Encryption Key Disclosure

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    nginxui · nginx ui5 Mar 2026

  • CVE-2024-23827
    39İzleyin

    Nginx-UI arbitrary file write through the Import Certificate feature

    KritikCVSS 9,8İstismar yokEPSS %1

    nginxui · nginx ui29 Oca 2024

  • CVE-2026-42222
    39İzleyin

    nginx-ui: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover

    KritikCVSS 9,8İstismar yokEPSS %0

    nginxui · nginx ui4 May 2026

  • CVE-2026-44015
    39İzleyin

    Nginx UI: Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware Allows Access to Internal Services

    KritikCVSS 9,9İstismar yokEPSS %0

    nginxui · nginx ui12 May 2026

  • CVE-2026-33030
    39İzleyin

    Nginx UI: Unencrypted Storage of DNS API Tokens and ACME Private Keys

    KritikCVSS 9,9İstismar yokEPSS %0

    nginxui · nginx ui30 Mar 2026

  • CVE-2026-33026
    37İzleyin

    nginx-ui Backup Restore Allows Tampering with Encrypted Backups

    KritikCVSS 9,4İstismar yokEPSS %0

    nginxui · nginx ui30 Mar 2026

  • CVE-2024-22198
    36İzleyin

    Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    nginxui · nginx ui11 Oca 2024

  • CVE-2026-42238
    36İzleyin

    Unauthenticated Remote Code Execution via Backup Restore in nginx-ui

    KritikCVSS 9,0İstismar yokEPSS %1

    nginxui · nginx ui4 May 2026

  • CVE-2024-22197
    35İzleyin

    Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)

    YüksekCVSS 8,8İstismar yokEPSS %2

    nginxui · nginx ui11 Oca 2024

  • CVE-2024-23828
    35İzleyin

    Nginx-UI authenticated RCE through injecting into the application config via CRLF

    YüksekCVSS 8,8İstismar yokEPSS %1

    nginxui · nginx ui29 Oca 2024

  • CVE-2026-33031
    34İzleyin

    Nginx-UI: Disabled users retain full API access through previously issued bearer tokens

    YüksekCVSS 8,6İstismar yokEPSS %0

    nginxui · nginx ui20 Nis 2026

  • CVE-2024-49366
    30İzleyin

    Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written

    YüksekCVSS 7,7İstismar yokEPSS %1

    nginxui · nginx ui21 Eki 2024

  • CVE-2026-33028
    28İzleyin

    Nginx UI: Race Condition Leads to Persistent Data Corruption and Service Collapse

    YüksekCVSS 7,1İstismar yokEPSS %1

    nginxui · nginx ui30 Mar 2026

  • CVE-2026-33027
    27İzleyin

    Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory

    OrtaCVSS 6,9İstismar yokEPSS %1

    nginxui · nginx ui30 Mar 2026

  • CVE-2026-33029
    27İzleyin

    Nginx UI: DoS via Negative Integer Input in Logrotate Interval

    OrtaCVSS 6,9İstismar yokEPSS %0

    nginxui · nginx ui30 Mar 2026

  • CVE-2024-22196
    26İzleyin

    Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)

    OrtaCVSS 6,5İstismar yokEPSS %1

    nginxui · nginx ui11 Oca 2024

  • CVE-2026-42223
    26İzleyin

    nginx-ui: Settings API Exposes Protected Secrets

    OrtaCVSS 6,5İstismar yokEPSS %0

    nginxui · nginx ui4 May 2026

  • CVE-2026-42220
    26İzleyin

    nginx-ui: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui s

    OrtaCVSS 6,5İstismar yokEPSS %0

    nginxui · nginx ui4 May 2026

  • CVE-2024-49367
    22İzleyin

    Nginx UI's log path can be controlled

    OrtaCVSS 5,5İstismar yokEPSS %1

    nginxui · nginx ui21 Eki 2024

  • CVE-2026-34403
    22İzleyin

    Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints

    OrtaCVSS 5,5İstismar yokEPSS %0

    nginxui · nginx ui20 Nis 2026