← Back to feed Search feed

nginx vulnerabilities

29 entries matching nginx — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-87935The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1HIGH8.144%ileNVD2026-09-17
DSA 6496-2[SECURITY] [DSA 6496-2] nginx regression updateHIGH8.1Debian2026-09-16
CVE-2026-55149Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in HIGH7.534%ileNVD2026-09-15
CVE-2026-90439NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL vMEDIUM6.918%ileNVD2026-09-15
CVE-2026-90937froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated cusCRITICAL9.418%ileNVD2026-09-14
CVE-2026-54723devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a MEDIUM6.525%ileNVD2026-09-14
CVE-2026-90651Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificHIGH8.19%ileNVD2026-09-13
CVE-2026-90581A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdLOW2.116%ileNVD2026-09-13
DSA 6496-1[SECURITY] [DSA 6496-1] nginx security updateHIGH8.2Debian2026-09-12
CVE-2026-18329NGINX ngx_http_js_module vulnerabilityHIGH8.232%ileMicrosoft2026-09-08
CVE-2026-78689NGINX ngx_http_js_module vulnerablilityHIGH8.139%ileMicrosoft2026-09-08
CVE-2026-78222NGINX ngx_http_js_module vulnerabilityHIGH7.531%ileMicrosoft2026-09-08
CVE-2015-0204OSSN-0045: = Vulnerable clients allow a TLS protocol downgrade (FREAK)=UNKNOWN100%ileOpenStack2026-08-27
CVE-2026-60005NGINX ngx_http_slice_module vulnerabilityHIGH8.252%ileMicrosoft2026-07-14
CVE-2026-42533NGINX Map directive and Regex matching vulnerabilityHIGH8.191%ileMicrosoft2026-07-14
CVE-2026-56434NGINX ngx_http_ssi_module vulnerabilityMEDIUM6.538%ileMicrosoft2026-07-14
CVE-2026-42055NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerabilityHIGH8.194%ileMicrosoft2026-06-09
CVE-2026-49975Apache HTTP Server: mod_http2 denial of serviceHIGH7.598%ileMicrosoft2026-06-09
CVE-2026-48142NGINX ngx_http_charset_module vulnerabilityMEDIUM4.851%ileMicrosoft2026-06-09
CVE-2026-42945NGINX ngx_http_rewrite_module vulnerabilityHIGH8.199%ileMicrosoft2026-05-12
CVE-2026-8711NGINX JavaScript vulnerabilityHIGH8.195%ileMicrosoft2026-05-12
CVE-2026-9256NGINX ngx_http_rewrite_module vulnerabilityHIGH8.196%ileMicrosoft2026-05-12
CVE-2026-40460NGINX ngx_quic_module vulnerabilityMEDIUM6.531%ileMicrosoft2026-05-12
CVE-2026-42946NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerabilityMEDIUM6.559%ileMicrosoft2026-05-12
CVE-2026-40701NGINX ngx_http_ssl_module vulnerabilityMEDIUM4.851%ileMicrosoft2026-05-12
CVE-2026-42934NGINX ngx_http_charset_module vulnerabilityMEDIUM4.853%ileMicrosoft2026-05-12
CVE-2025-53859NGINX ngx_mail_smtp_module vulnerabilityMEDIUM5.633%ileMicrosoft2025-08-12
CVE-2020-19692Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njsCRITICAL9.870%ileMicrosoft2023-04-11
CVE-2020-19695Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameCRITICAL9.870%ileMicrosoft2023-04-11