<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – nginx (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/nginx.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nginx-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – nginx (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:36 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-9508 – Incorrect permission settings on a critical resource in Suprema BioStar 2 (versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9508</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9508</guid>
    <pubDate>Fri, 29 May 2026 13:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-9508</strong></p>
  <p>Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path within the NGINX webroot. This vulnerability allows an attacker with network access to directly download backup ZIP files via ‘http(s)://[server]/download/…’ without requiring authentication. This expo…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9508">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-9256 – NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-9256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-9256</guid>
    <pubDate>Fri, 22 May 2026 15:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-9256</strong></p>
  <p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for example, ^/((.*))$) and a replacement string that references multiple such captures (for example, $1$2) in a redirect or arguments context. An unauthen…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-9256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8711 – NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is config...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8711</guid>
    <pubDate>Tue, 19 May 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8711</strong></p>
  <p>NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX work…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46356 – Fleet is open source device management software. Prior to version 4.80.1, a vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46356</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46356</guid>
    <pubDate>Thu, 14 May 2026 20:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46356</strong></p>
  <p>Fleet is open source device management software. Prior to version 4.80.1, a vulnerability in Fleet's IP extraction logic allows unauthenticated attackers to bypass API rate limiting by spoofing client IP headers. This may allow brute-force login attempts or other abuse against Fleet instances exposed to the public internet. Fleet extracted client IP addresses from request headers (`True-Client-IP…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46356">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42945 – NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42945</guid>
    <pubDate>Wed, 13 May 2026 16:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42945</strong></p>
  <p>NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond i…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39806 – Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39806</guid>
    <pubDate>Wed, 13 May 2026 14:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39806</strong></p>
  <p>Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion.  'Elixir.Bandit.HTTP1.Socket':do_read_chunked_data!/5 in lib/bandit/http1/socket.ex terminates only when the last-chunk line 0\r\n is followed immediately by the empty trailer line \r\n. RFC 9112 §7.1.2 permits zero or more trailer f…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44015 – Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44015</guid>
    <pubDate>Tue, 12 May 2026 22:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44015</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Side Request Forgery (SSRF) by creating a cluster node pointing to an arbitrary internal URL and then sending API requests with the X-Node-ID header. The Proxy middleware forwards these requests to the attacker-specified internal address, bypassing network segmentation and ena…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42268 – ModSecurity is an open source, cross platform web application firewall (WAF) eng...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42268</guid>
    <pubDate>Tue, 12 May 2026 22:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42268</strong></p>
  <p>ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused by unsigned integer underflow in libmodsecurity3 if the user (administrator) uses a rule any of @verifySSN, @verifyCPF, or @verifySVNR. This vulnerability is fixed in 3.0.15.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-191</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8430 – SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8430</guid>
    <pubDate>Tue, 12 May 2026 19:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8430</strong></p>
  <p>SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the context of the web server. Attackers can exploit this vulnerability through specific nginx configuration scenarios to achieve code execution, and this issue is not mitigated by the SPIP security screen.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30923 – ModSecurity is an open source, cross platform web application firewall (WAF) eng...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30923</guid>
    <pubDate>Tue, 05 May 2026 19:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30923</strong></p>
  <p>ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occurs when a rule using the t:hexDecode transformation inspects a query string parameter containing a single character. An attacker can exploit this to crash worker processes, causing a denial of service…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42238 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42238</guid>
    <pubDate>Mon, 04 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42238</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQL…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42222 – Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42222</guid>
    <pubDate>Mon, 04 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42222</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in nginx-ui during the initial installation window exposed by POST /api/install. At time of publication no public patches are available.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42221 – Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42221</guid>
    <pubDate>Mon, 04 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42221</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated network attacker can claim the initial administrator account on a fresh nginx-ui instance during the first-run setup window. The public /api/install endpoint is reachable without authentication, and the request-encryption flow only protects payload confidentiality in transit;…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-7381 – Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7381</guid>
    <pubDate>Wed, 29 Apr 2026 23:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-7381</strong></p>
  <p>Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting.  Plack::Middleware::XSendfile allows the variation setting (sendfile type) to be set by the client via the X-Sendfile-Type header, if it is not considered in the middleware constructor or the Plack environment.  A malicious client can set the X-Sendfile-Type header to "X-Accel-Redirect" to se…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33208 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33208</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33208</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in Roxy-WI fails to sanitize the user-supplied words parameter before embedding it into a shell command string that is subsequently executed on a remote managed server via SSH. An authenticated attacker can inject arbitrary shell metach…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33078 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33078</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33078</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save function in app/routes/config/routes.py. The server_ip parameter, sourced from the URL path, is passed unsanitized through multiple function calls and ultimately interpolated into a SQL query string using Python string form…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33077 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33077</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33077</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33076 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33076</guid>
    <pubDate>Fri, 24 Apr 2026 03:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33076</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40575 – OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 provid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40575</guid>
    <pubDate>Wed, 22 Apr 2026 00:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40575</strong></p>
  <p>OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header so OAuth2 Proxy evaluates authentication and skip-auth rules against a different path than the one ac…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34403 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34403</guid>
    <pubDate>Mon, 20 Apr 2026 21:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34403</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true, allowing Cross-Site WebSocket Hijacking (CSWSH). Combined with the fact that authentication tokens are stored in browser cookies (set via JavaScript without HttpOnly or explicit SameSite attributes)…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-1385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33432 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33432</guid>
    <pubDate>Mon, 20 Apr 2026 21:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33432</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search filter by directly concatenating the user-supplied login username into the filter string without escaping LDAP special characters. An unauthenticated attacker can inject LDAP filter metacharacters int…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33031 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33031</guid>
    <pubDate>Mon, 20 Apr 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33031</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In practice, disabling a compromised account does not actually terminate that user’s access, so an attacker who already stole a JWT can continue reading and modifying protected resources after the account…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40487 – Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40487</guid>
    <pubDate>Sat, 18 Apr 2026 02:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40487</strong></p>
  <p>Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, SVG, or other executable file types to the server by spoofing the `Content-Type` header. The uploaded files are then served by nginx with a Content-Type derived from their original extension (`text/html`, `image/svg+xml`), enabling Stored C…</p>
  <p><strong>CVSS:</strong> 8.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-34457 – OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 provid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34457</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34457</guid>
    <pubDate>Tue, 14 Apr 2026 23:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-34457</strong></p>
  <p>OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a configuration-dependent authentication bypass in deployments where OAuth2 Proxy is used with an auth_request-style integration (such as nginx auth_request) and either --ping-user-agent is set or --gcp-healthchecks is enabled. In affected configurations, OAuth2 Proxy treats any r…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34457">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5501 – wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5501</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5501</guid>
    <pubDate>Fri, 10 Apr 2026 04:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5501</strong></p>
  <p>wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the leaf's signature is not checked, if the attacker supplies an untrusted intermediate with Basic Constraints `CA:FALSE` that is legitimately signed by a trusted root. An attacker who obtains any leaf certificate from a trusted CA (e.g. a free DV cert from Let's Encrypt) can forge a certificate for a…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5501">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31842 – Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31842</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31842</guid>
    <pubDate>Tue, 07 Apr 2026 12:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31842</strong></p>
  <p>Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer() function uses strcmp() to compare the header value against "chunked", even though RFC 7230 specifies that transfer-coding names are case-insensitive. By sending a request with Transfer-Encoding: Chunked, an una…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31842">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34759 – OneUptime is an open-source monitoring and observability platform. Prior to vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34759</guid>
    <pubDate>Thu, 02 Apr 2026 19:21:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34759</strong></p>
  <p>OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use ClusterKeyAuthorization.isAuthorizedServiceMiddleware. These endpoints are externally reachable via the Nginx proxy at /notification/. Combined with a projectId…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33026 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33026</guid>
    <pubDate>Mon, 30 Mar 2026 20:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33026</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has been patched in version 2.3.4.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33026">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-33032 – Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33032</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33032</guid>
    <pubDate>Mon, 30 Mar 2026 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-33032</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authentication (AuthRequired() middleware), the /mcp_message endpoint only applies IP whitelisting - and the default IP whitelist is empty, which the middleware…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33032">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33030 – Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33030</guid>
    <pubDate>Mon, 30 Mar 2026 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33030</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to other users. The application's base Model struct lacks a user_id field, and all resource endpoints perform queries by ID without verifying user owne…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33028 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33028</guid>
    <pubDate>Mon, 30 Mar 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33028</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration file (app.ini). This vulnerability results in a persistent Denial of Service (DoS)…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32647 – NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32647</guid>
    <pubDate>Tue, 24 Mar 2026 15:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32647</strong></p>
  <p>NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to trigger a buffer over-read or over-write to the NGINX worker memory resulting in its termination or possibly code execution, using a specially crafted MP4 file. This issue affects NGINX Open Source and NGINX Plus if it is built with the ngx_http_mp4_module module and the mp4 d…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27784 – The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_ht...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27784</guid>
    <pubDate>Tue, 24 Mar 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27784</strong></p>
  <p>The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow an attacker to over-read or over-write NGINX worker memory resulting in its termination, using a specially crafted MP4 file. The issue only affects 32-bit NGINX Open Source if it is built with the ngx_http_mp4_module module and the mp4 directive is used in the configuration file…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27654 – NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27654</guid>
    <pubDate>Tue, 24 Mar 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27654</strong></p>
  <p>NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to trigger a buffer overflow to the NGINX worker process; this vulnerability may result in termination of the NGINX worker process or modification of source or destination file names outside the document root. This issue affects NGINX Open Source and NGINX Plus when the configurati…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27651 – When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27651</guid>
    <pubDate>Tue, 24 Mar 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27651</strong></p>
  <p>When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-4342 – A security issue was discovered in ingress-nginx where a combination of Ingress ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4342</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-4342</strong></p>
  <p>A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3547 – Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3547</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3547</guid>
    <pubDate>Thu, 19 Mar 2026 21:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3547</strong></p>
  <p>Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list could trigger an out-of-bounds read, leading to a potential process crash (denial of service). Note that ALPN is disabled by default, but is enabled for these 3rd party com…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3547">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32255 – Kan is an open-source project management tool. In versions 0.5.4 and below, the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32255</guid>
    <pubDate>Thu, 19 Mar 2026 00:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32255</strong></p>
  <p>Kan is an open-source project management tool. In versions 0.5.4 and below, the /api/download/attatchment endpoint has no authentication and no URL validation. The Attachment Download endpoint accepts a user-supplied URL query parameter and passes it directly to fetch() server-side, and returns the full response body. An unauthenticated attacker can use this to make HTTP requests from the server…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27811 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27811</guid>
    <pubDate>Wed, 18 Mar 2026 00:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27811</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability exists in the `/config/compare/<service>/<server_ip>/show` endpoint, allowed authenticated users to execute arbitrary system commands on the app host. The vulnerability exists in `app/modules/config/config.py` on line 362, where user input is directly…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23941 – Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23941</guid>
    <pubDate>Fri, 13 Mar 2026 19:54:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23941</strong></p>
  <p>Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling.  This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7.  The server does not reject or normalize duplicate Content-Length headers. The earliest Content-Le…</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3288 – A security issue was discovered in ingress-nginx where the `nginx.ingress.kubern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3288</guid>
    <pubDate>Mon, 09 Mar 2026 21:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3288</strong></p>
  <p>A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets clus…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27944 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27944</guid>
    <pubDate>Thu, 05 Mar 2026 19:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27944</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header. This allows an unauthenticated attacker to download a full system backup containing sensitive data (user credentials, session tokens, SSL private k…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27633 – TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27633</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27633</guid>
    <pubDate>Thu, 26 Feb 2026 00:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27633</strong></p>
  <p>TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Service (DoS) vulnerability via memory exhaustion. Unauthenticated remote attackers can send an HTTP POST request to the server with an exceptionally large `Content-Length` header (e.g., `2147483647`). The server continuously allocates memory for the request body (`EntityBody`) while…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27633">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27630 – TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27630</guid>
    <pubDate>Thu, 26 Feb 2026 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27630</strong></p>
  <p>TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a Denial of Service (DoS) attack known as Slowloris. The server spawns a new OS thread for every incoming connection without enforcing a maximum concurrency limit or an appropriate request timeout. An unauthenticated remote attacker can exhaust server concurrency limits and memory b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15566 – A security issue was discovered in ingress-nginx where the `nginx.ingress.kubern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15566</guid>
    <pubDate>Fri, 06 Feb 2026 04:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15566</strong></p>
  <p>A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secr…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24512 – A security issue was discovered in ingress-nginx where the `rules.http.paths.pat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24512</guid>
    <pubDate>Tue, 03 Feb 2026 23:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24512</strong></p>
  <p>A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1580 – A security issue was discovered in ingress-nginx where the `nginx.ingress.kubern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1580</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1580</guid>
    <pubDate>Tue, 03 Feb 2026 23:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1580</strong></p>
  <p>A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1580">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1616 – The $uri$args concatenation in nginx configuration file present in Open Security...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1616</guid>
    <pubDate>Thu, 29 Jan 2026 14:16:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1616</strong></p>
  <p>The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-23837 – MyTube is a self-hosted downloader and player for several video websites. A vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23837</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23837</guid>
    <pubDate>Mon, 19 Jan 2026 21:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-23837</strong></p>
  <p>MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMiddleware. By simply not providing an authentication cookie (making req.user undefined), a request is incorrectly passed through to downstream handlers. Al…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23837">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23838 – Tandoor Recipes is a recipe manager than can be installed with the Nix package m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23838</guid>
    <pubDate>Mon, 19 Jan 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23838</strong></p>
  <p>Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the full database file may be externally accessible, potentially on the Internet. The root cause is that the NixOS module configures the working dir…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22265 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22265</guid>
    <pubDate>Thu, 15 Jan 2026 17:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22265</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py line 87, where the grep parameter is used twice - once sanitized and once raw. This vulnerability is…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14727 – A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14727</guid>
    <pubDate>Wed, 17 Dec 2025 16:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14727</strong></p>
  <p>A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67731 – Servify Express is a Node.js package to start an Express server and log the port...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67731</guid>
    <pubDate>Fri, 12 Dec 2025 08:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67731</strong></p>
  <p>Servify Express is a Node.js package to start an Express server and log the port it's running on. Prior to 1.2, the Express server used express.json() without a size limit, which could allow attackers to send extremely large request bodies. This can cause excessive memory usage, degraded performance, or process crashes, resulting in a Denial of Service (DoS). Any application using the JSON parser…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-66570 – cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66570</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66570</guid>
    <pubDate>Fri, 05 Dec 2025 19:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-66570</strong></p>
  <p>cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visible metadata, logging, and authorization decisions. An attacker can inject headers named REMOTE_ADDR, REMOTE_PORT, LOCAL_ADDR, LOCAL_PORT that are parsed into the request header multimap via read_headers() in httplib.h (…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66570">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13516 – The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13516</guid>
    <pubDate>Tue, 02 Dec 2025 09:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13516</strong></p>
  <p>The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessible directory (wp-content/uploads/suremails/attachments/) without validating file extensions or conte…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61919 – Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61919</guid>
    <pubDate>Fri, 10 Oct 2025 20:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61919</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the entire request body into memory for `Content-Type: application/x-www-form-urlencoded`, calling `rack.input.read(nil)` without enforcing a length or cap. Large request bodies can therefore be buffered completely into process memory before parsing, leading to denial of service (D…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61772 – Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61772</guid>
    <pubDate>Tue, 07 Oct 2025 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61772</strong></p>
  <p>Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, `Rack::Multipart::Parser` can accumulate unbounded data when a multipart part’s header block never terminates with the required blank line (`CRLFCRLF`). The parser keeps appending incoming bytes to memory without a size cap, allowing a remote attacker to exhaust memory and cause a denial of service (DoS).…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61771 – Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61771</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61771</guid>
    <pubDate>Tue, 07 Oct 2025 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61771</strong></p>
  <p>Rack is a modular Ruby web server interface. In versions prior to 2.2.19, 3.1.17, and 3.2.2, ``Rack::Multipart::Parser` stores non-file form fields (parts without a `filename`) entirely in memory as Ruby `String` objects. A single large text field in a multipart/form-data request (hundreds of megabytes or more) can consume equivalent process memory, potentially leading to out-of-memory (OOM) cond…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61771">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-59951 – Termix is a web-based server management platform with SSH terminal, tunneling, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59951</guid>
    <pubDate>Wed, 01 Oct 2025 22:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-59951</strong></p>
  <p>Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image  for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the backend to retrieve the proxy's IP instead of the client's IP when using the req.ip method. This results in isLocalhost always returning True. Consequently, the…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-34203 – Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34203</guid>
    <pubDate>Fri, 19 Sep 2025 19:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-34203</strong></p>
  <p>Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior to 20.0.2614 (VA and SaaS deployments) contain multiple Docker containers that include outdated, end-of-life, unsupported, or otherwise vulnerable third-party components (examples: Nginx 1.17.x, OpenSSL 1.1.1d, various EOL Alpine/Debian/Ubuntu base images, and EOL Laravel/PHP lib…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49564 – The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49564</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49564</guid>
    <pubDate>Thu, 18 Sep 2025 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49564</strong></p>
  <p>The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API functions. This flaw allows attackers to reach restricted or sensitive endpoints of the HTTP API without providing any valid credentials. The root cause of this vulnerability lies in a weak verification mechanism within the aut…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49564">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58362 – Hono is a Web application framework that provides support for any JavaScript run...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58362</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58362</guid>
    <pubDate>Fri, 05 Sep 2025 00:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58362</strong></p>
  <p>Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 contain a flaw in the getPath utility function which could allow path confusion and potential bypass of proxy-level ACLs (e.g. Nginx location blocks). The original implementation relied on fixed character offsets when parsing request URLs. Under certain malformed absolute-form Reques…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-706</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58362">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-58048 – Paymenter is a free and open-source webshop solution for hostings. Prior to vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58048</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58048</guid>
    <pubDate>Thu, 28 Aug 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-58048</strong></p>
  <p>Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands being run under the web server user context. Th…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58048">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6213 – The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6213</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6213</guid>
    <pubDate>Tue, 22 Jul 2025 10:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6213</strong></p>
  <p>The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER['HTTP_REFERERER'] parameter passed from the 'nppp_handle_fastcgi_cache_actions_admin_bar' function. This makes it possible for authenticated attackers, with Ad…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6213">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-5961 – The Migration, Backup, Staging – WPvivid Backup &amp; Migration plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5961</guid>
    <pubDate>Thu, 03 Jul 2025 14:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-5961</strong></p>
  <p>The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpvivid_upload_import_files' function in all versions up to, and including, 0.9.116. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's serve…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50202 – Lychee is a free photo-management tool. In versions starting from 6.6.6 to befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50202</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50202</guid>
    <pubDate>Wed, 18 Jun 2025 05:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50202</strong></p>
  <p>Lychee is a free photo-management tool. In versions starting from 6.6.6 to before 6.6.10, an attacker can leak local files including environment variables, nginx logs, other user's uploaded images, and configuration secrets due to a path traversal exploit in SecurePathController.php. This issue has been patched in version 6.6.10.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50202">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48866 – ModSecurity is an open source, cross platform web application firewall (WAF) eng...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48866</guid>
    <pubDate>Mon, 02 Jun 2025 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48866</strong></p>
  <p>ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to adding an excessive number of arguments, thereby leading to denial of service. V…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1050</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-47947 – ModSecurity is an open source, cross platform web application firewall (WAF) eng...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-47947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-47947</guid>
    <pubDate>Wed, 21 May 2025 22:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-47947</strong></p>
  <p>ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions up to and including 2.9.8 are vulnerable to denial of service in one special case (in stable released versions): when the payload's content type is `application/json`, and there is at least one rule which does a `sanitiseMatchedBytes` action. A patch is available at pull request…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1050</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-47947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-30207 – Kirby is an open-source content management system. A vulnerability in versions p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30207</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30207</guid>
    <pubDate>Tue, 13 May 2025 16:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-30207</strong></p>
  <p>Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby setups that use PHP's built-in server. Such setups are commonly only used during local development. Sites that use other server software (such as Apache, nginx or Caddy) are not affected. A missing path traversal check allowed attackers to navigate all files on th…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30207">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46727 – Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46727</guid>
    <pubDate>Wed, 07 May 2025 23:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46727</strong></p>
  <p>Rack is a modular Ruby web server interface. Prior to versions 2.2.14, 3.0.16, and 3.1.14, `Rack::QueryParser` parses query strings and `application/x-www-form-urlencoded` bodies into Ruby data structures without imposing any limit on the number of parameters, allowing attackers to send requests with extremely large numbers of parameters. The vulnerability arises because `Rack::QueryParser` itera…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46728 – cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46728</guid>
    <pubDate>Tue, 06 May 2025 01:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46728</strong></p>
  <p>cpp-httplib is a C++ header-only HTTP/HTTPS server and client library. Prior to version 0.20.1, the library fails to enforce configured size limits on incoming request bodies when `Transfer-Encoding: chunked` is used or when no `Content-Length` header is provided. A remote attacker can send a chunked request without the terminating zero-length chunk, causing uncontrolled memory allocation on the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-33452 – An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-33452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-33452</guid>
    <pubDate>Tue, 22 Apr 2025 16:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-33452</strong></p>
  <p>An issue in OpenResty lua-nginx-module v.0.10.26 and before allows a remote attacker to conduct HTTP request smuggling via a crafted HEAD request.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-33452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2787 – KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a Ingres...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2787</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2787</guid>
    <pubDate>Wed, 26 Mar 2025 21:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2787</strong></p>
  <p>KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete takeover of the Kubernetes cluster is possible. Since the affected component is only reachable from within the cluster, i.e. requires an authenticated user, the severity in the context of KNIME Business Hub is slightly l…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2787">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24514 – A security issue was discovered in  ingress-nginx https://github.com/kubernetes/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24514</guid>
    <pubDate>Tue, 25 Mar 2025 00:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24514</strong></p>
  <p>A security issue was discovered in  ingress-nginx https://github.com/kubernetes/ingress-nginx  where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-1974 – A security issue was discovered in Kubernetes where under certain conditions, an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1974</guid>
    <pubDate>Tue, 25 Mar 2025 00:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-1974</strong></p>
  <p>A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-653</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1098 – A security issue was discovered in  ingress-nginx https://github.com/kubernetes/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1098</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1098</guid>
    <pubDate>Tue, 25 Mar 2025 00:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1098</strong></p>
  <p>A security issue was discovered in  ingress-nginx https://github.com/kubernetes/ingress-nginx  where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installati…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1098">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1097 – A security issue was discovered in  ingress-nginx https://github.com/kubernetes/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1097</guid>
    <pubDate>Tue, 25 Mar 2025 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1097</strong></p>
  <p>A security issue was discovered in  ingress-nginx https://github.com/kubernetes/ingress-nginx  where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can ac…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49698 – In the Linux kernel, the following vulnerability has been resolved:

netfilter: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49698</guid>
    <pubDate>Wed, 26 Feb 2025 07:01:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49698</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  netfilter: use get_random_u32 instead of prandom  bh might occur while updating per-cpu rnd_state from user context, ie. local_out path.  BUG: using smp_processor_id() in preemptible [00000000] code: nginx/2725 caller is nft_ng_random_eval+0x24/0x54 [nft_numgen] Call Trace:  check_preemption_disabled+0xde/0xe0  nft_ng_random_eva…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-13869 – The Migration, Backup, Staging – WPvivid Backup &amp; Migration plugin for WordPress...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-13869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-13869</guid>
    <pubDate>Sat, 22 Feb 2025 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-13869</strong></p>
  <p>The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_files' function in all versions up to, and including, 0.9.112. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may mak…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-13869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-53991 – Discourse is an open source platform for community discussion. This vulnerabilit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53991</guid>
    <pubDate>Thu, 19 Dec 2024 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-53991</strong></p>
  <p>Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of the Discourse backup file, the attacker can trick nginx into sending the Discourse backup file with a well crafted request. This issue is patched in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10590 – The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file upload...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10590</guid>
    <pubDate>Thu, 12 Dec 2024 05:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10590</strong></p>
  <p>The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_upload() function in all versions up to, and including, 4.07. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. Due to the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-49368 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49368</guid>
    <pubDate>Mon, 21 Oct 2024 17:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-49368</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49367 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49367</guid>
    <pubDate>Mon, 21 Oct 2024 17:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49367</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49366 – Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49366</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49366</guid>
    <pubDate>Mon, 21 Oct 2024 17:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49366</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26 fixes the issue.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49366">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-43804 – Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-43804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-43804</guid>
    <pubDate>Thu, 29 Aug 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-43804</strong></p>
  <p>Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied input is used without validation when constructing and executing an OS command. User supplied JSON POST data is parsed and…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-43804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7646 – A security issue was discovered in ingress-nginx where an actor with permission ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7646</guid>
    <pubDate>Fri, 16 Aug 2024 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7646</strong></p>
  <p>A security issue was discovered in ingress-nginx where an actor with permission to create Ingress objects (in the `networking.k8s.io` or `extensions` API group) can bypass annotation validation to inject arbitrary commands and obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39792 – When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39792</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39792</guid>
    <pubDate>Wed, 14 Aug 2024 15:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39792</strong></p>
  <p>When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-825</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39792">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-41668 – The cBioPortal for Cancer Genomics provides visualization, analysis, and downloa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41668</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41668</guid>
    <pubDate>Tue, 23 Jul 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-41668</strong></p>
  <p>The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, cBioPortal could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances. A fix has been released in version 6.0.12. As a workaround, o…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41668">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-39935 – jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39935</guid>
    <pubDate>Thu, 04 Jul 2024 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-39935</strong></p>
  <p>jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS provider configuration. NOTE: this is not part of any NGINX software shipped by F5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3149 – A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link fea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3149</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3149</guid>
    <pubDate>Thu, 06 Jun 2024 19:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3149</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headless browser. An attacker can exploit this by hosting a malicious website and using it to perform actions such as internal port scanning, accessing in…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3149">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-39481 – Softing Secure Integration Server Interpretation Conflict Remote Code Execution ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39481</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39481</guid>
    <pubDate>Fri, 03 May 2024 03:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-39481</strong></p>
  <p>Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.  The specific flaw exists within the web server.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39481">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-28101 – The Apollo Router is a graph router written in Rust to run a federated supergrap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-28101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-28101</guid>
    <pubDate>Thu, 21 Mar 2024 02:52:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-28101</strong></p>
  <p>The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router evaluate the `limits.http_max_request_bytes` configuration option after the entirety of the compressed payload is decompressed…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-28101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24990 – When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24990</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24990</strong></p>
  <p>When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.  Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to  Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .        Note: Software versions which have reached End of Technical Sup…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24989 – When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24989</guid>
    <pubDate>Wed, 14 Feb 2024 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24989</strong></p>
  <p>When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate.  Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to  Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html .    NOTE: Software versions which have reached End of Technical Support…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23828 – Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23828</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23828</guid>
    <pubDate>Mon, 29 Jan 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23828</strong></p>
  <p>Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value of test_config_cmd or start_cmd. This vulnerability exists due to an incomplete fix for CVE-2024-22197 and CVE-2024-22198. This vulnerability has been patched in version 2.0.0.beta.12.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23828">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23827 – Nginx-UI is a web interface to manage Nginx configurations. The Import Certifica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23827</guid>
    <pubDate>Mon, 29 Jan 2024 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23827</strong></p>
  <p>Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitrary paths in the system. It's possible to leverage the vulnerability into a remote code execution overwriting the config file app.ini. Version 2.0.0.beta.12 fix…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-50919 – An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-50919</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-50919</guid>
    <pubDate>Fri, 12 Jan 2024 08:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-50919</strong></p>
  <p>An issue was discovered on GL.iNet devices before version 4.5.0. There is an NGINX authentication bypass via Lua string pattern matching. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-50919">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22198 – Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22198</guid>
    <pubDate>Thu, 11 Jan 2024 20:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22198</strong></p>
  <p>Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secret`, `Node Secret` and `Terminal Start Command`. While the UI doesn't allow users to modify the `Terminal Start Command` setting, it is possible to do so by sen…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22196 – Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22196</guid>
    <pubDate>Thu, 11 Jan 2024 20:15:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22196</strong></p>
  <p>Nginx-UI is an online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using `DefaultQuery`, the `"desc"` and `"id"` values are used as default values if the query parameters are not set. Thus, the `order` and `sort_by` query parameter are user-controlled and are being appended to the `…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22196">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22197 – Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22197</guid>
    <pubDate>Thu, 11 Jan 2024 18:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22197</strong></p>
  <p>Nginx-ui is online statistics for Server Indicators​​ Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `Nginx Error Log Path`. However, the API also exposes `test_config_cmd`, `reload_cmd` and `restart_cmd`. While the UI doesn't allow users to modify any of these sett…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22197">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
