29 entries matching nginx — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-87935 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1 | HIGH | 8.1 | 44%ile | NVD | 2026-09-17 |
| DSA 6496-2 | [SECURITY] [DSA 6496-2] nginx regression update | HIGH | 8.1 | — | Debian | 2026-09-16 |
| CVE-2026-55149 | Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in | HIGH | 7.5 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-90439 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL v | MEDIUM | 6.9 | 18%ile | NVD | 2026-09-15 |
| CVE-2026-90937 | froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated cus | CRITICAL | 9.4 | 18%ile | NVD | 2026-09-14 |
| CVE-2026-54723 | devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a | MEDIUM | 6.5 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-90651 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certific | HIGH | 8.1 | 9%ile | NVD | 2026-09-13 |
| CVE-2026-90581 | A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpd | LOW | 2.1 | 16%ile | NVD | 2026-09-13 |
| DSA 6496-1 | [SECURITY] [DSA 6496-1] nginx security update | HIGH | 8.2 | — | Debian | 2026-09-12 |
| CVE-2026-18329 | NGINX ngx_http_js_module vulnerability | HIGH | 8.2 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-78689 | NGINX ngx_http_js_module vulnerablility | HIGH | 8.1 | 39%ile | Microsoft | 2026-09-08 |
| CVE-2026-78222 | NGINX ngx_http_js_module vulnerability | HIGH | 7.5 | 31%ile | Microsoft | 2026-09-08 |
| CVE-2015-0204 | OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)= | UNKNOWN | — | 100%ile | OpenStack | 2026-08-27 |
| CVE-2026-60005 | NGINX ngx_http_slice_module vulnerability | HIGH | 8.2 | 52%ile | Microsoft | 2026-07-14 |
| CVE-2026-42533 | NGINX Map directive and Regex matching vulnerability | HIGH | 8.1 | 91%ile | Microsoft | 2026-07-14 |
| CVE-2026-56434 | NGINX ngx_http_ssi_module vulnerability | MEDIUM | 6.5 | 38%ile | Microsoft | 2026-07-14 |
| CVE-2026-42055 | NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability | HIGH | 8.1 | 94%ile | Microsoft | 2026-06-09 |
| CVE-2026-49975 | Apache HTTP Server: mod_http2 denial of service | HIGH | 7.5 | 98%ile | Microsoft | 2026-06-09 |
| CVE-2026-48142 | NGINX ngx_http_charset_module vulnerability | MEDIUM | 4.8 | 51%ile | Microsoft | 2026-06-09 |
| CVE-2026-42945 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 99%ile | Microsoft | 2026-05-12 |
| CVE-2026-8711 | NGINX JavaScript vulnerability | HIGH | 8.1 | 95%ile | Microsoft | 2026-05-12 |
| CVE-2026-9256 | NGINX ngx_http_rewrite_module vulnerability | HIGH | 8.1 | 96%ile | Microsoft | 2026-05-12 |
| CVE-2026-40460 | NGINX ngx_quic_module vulnerability | MEDIUM | 6.5 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-42946 | NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability | MEDIUM | 6.5 | 59%ile | Microsoft | 2026-05-12 |
| CVE-2026-40701 | NGINX ngx_http_ssl_module vulnerability | MEDIUM | 4.8 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-42934 | NGINX ngx_http_charset_module vulnerability | MEDIUM | 4.8 | 53%ile | Microsoft | 2026-05-12 |
| CVE-2025-53859 | NGINX ngx_mail_smtp_module vulnerability | MEDIUM | 5.6 | 33%ile | Microsoft | 2025-08-12 |
| CVE-2020-19692 | Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs | CRITICAL | 9.8 | 70%ile | Microsoft | 2023-04-11 |
| CVE-2020-19695 | Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parame | CRITICAL | 9.8 | 70%ile | Microsoft | 2023-04-11 |