VYPR
Vendor

Nginx

Products
20
CVEs
144
Across products
171
Status
Private

Products

20

Recent CVEs

144
View all 144 CVEs →
  • CVE-2024-49368CriOct 21, 2024
    risk 0.66cvss 9.8epss 0.27

    Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.

  • CVE-2020-19695CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.

  • CVE-2020-19692CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.

  • CVE-2019-13067CriJun 30, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place.

  • CVE-2019-12208CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c.

  • CVE-2019-12207CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c.

  • CVE-2019-12206CriMay 20, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c.

  • CVE-2019-11839CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.

  • CVE-2019-11838CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.

  • CVE-2019-7401CriFeb 8, 2019
    risk 0.64cvss 9.8epss 0.03

    NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.

  • CVE-2016-0746CriFeb 15, 2016
    risk 0.64cvss 9.8epss 0.09

    Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response…

  • CVE-2020-5901CriJul 1, 2020
    risk 0.63cvss 9.6epss 0.01

    In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

  • CVE-2022-34029CriJul 18, 2022
    risk 0.59cvss 9.1epss 0.01

    Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.

  • CVE-2026-42945HigMay 13, 2026
    risk 0.58cvss 8.1epss 0.66

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1,…

  • CVE-2021-23017HigJun 1, 2021
    risk 0.57cvss 7.7epss 0.53

    A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

  • CVE-2020-5863HigMar 27, 2020
    risk 0.56cvss 8.6epss 0.01

    In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components…

  • CVE-2026-27654HigMar 24, 2026
    risk 0.55cvss 8.2epss 0.22

    NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or…

  • CVE-2016-0742HigFeb 15, 2016
    risk 0.55cvss 7.5epss 0.82

    The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

  • CVE-2025-14727HigDec 17, 2025
    risk 0.54cvss 8.3epss 0.00

    A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2017-7529HigJul 13, 2017
    risk 0.54cvss 7.5epss 0.63

    Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.