Vulnerabilities

Last updated 35 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/0xJacky/Nginx-UI Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout Medium Risk 5.3 53 minutes ago 35 minutes ago
github.com/0xJacky/Nginx-UI Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage High Risk 7.5 53 minutes ago 35 minutes ago
github.com/0xJacky/Nginx-UI Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite Critical 9.5 1 hour ago 50 minutes ago
github.com/0xJacky/Nginx-UI 0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser High Risk 8.8 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up High Risk 8.8 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI Nginx UI: Node Secret Credential Exposure via URL Query Parameter High Risk 8.8 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs High Risk 8.8 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass) High Risk 8.1 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM High Risk 7.5 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied High Risk 8.1 4 hours ago 4 hours ago
github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse High Risk 8.0 6 months ago 29 days ago
github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation Medium Risk 6.0 6 months ago 29 days ago
github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover Critical 9.8 6 months ago 29 days ago
github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval Medium Risk 6.0 6 months ago 29 days ago
github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys High Risk 8.8 6 months ago 29 days ago
github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback Medium Risk 6.5 5 months ago 2 months ago
github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups Critical 9.5 6 months ago 3 months ago
github.com/0xJacky/Nginx-UI Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270) High Risk 7.0 2 years ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF High Risk 8.8 2 years ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature Critical 9.8 2 years ago 3 months ago
github.com/0xJacky/Nginx-UI Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268) High Risk 7.1 2 years ago 3 months ago
github.com/0xJacky/Nginx-UI Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269) High Risk 7.7 2 years ago 3 months ago
github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover High Risk 8.1 5 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens High Risk 8.1 5 months ago 3 months ago
github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets Medium Risk 6.5 5 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services High Risk 8.5 5 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim High Risk 8.1 5 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI Unknown 3 months ago 3 months ago
github.com/0xJacky/nginx-ui Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui Unknown 3 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI Unknown 3 months ago 3 months ago
github.com/0xJacky/nginx-ui Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui Unknown 3 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI Unknown 3 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints High Risk 8.1 5 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI Unknown 3 months ago 3 months ago
github.com/0xJacky/Nginx-UI Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI Unknown 3 months ago 3 months ago
github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore Critical 9.8 5 months ago 3 months ago
github.com/0xJacky/nginx-ui Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui Unknown 3 months ago 3 months ago
github.com/0xJacky/nginx-ui nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui Unknown 6 months ago 6 months ago
github.com/0xJacky/Nginx-UI nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI Unknown 6 months ago 6 months ago
github.com/0xJacky/Nginx-UI nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI Unknown 6 months ago 6 months ago
github.com/0xJacky/Nginx-UI Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI Unknown 6 months ago 6 months ago
github.com/0xJacky/Nginx-UI nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI Unknown 6 months ago 6 months ago
github.com/0xJacky/Nginx-UI nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI Unknown 6 months ago 6 months ago
github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure Critical 9.8 7 months ago 6 months ago
github.com/0xJacky/Nginx-UI Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI Unknown 7 months ago 6 months ago
github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI Unknown 2 years ago 2 years ago
github.com/0xJacky/Nginx-UI Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI Unknown 2 years ago 2 years ago
github.com/0xJacky/Nginx-UI Arbitrary command execution in github.com/0xJacky/Nginx-UI Unknown 2 years ago 2 years ago
github.com/0xJacky/Nginx-UI SQL injection in github.com/0xJacky/Nginx-UI Unknown 2 years ago 2 years ago
github.com/0xJacky/Nginx-UI Remote command execution in github.com/0xJacky/Nginx-UI Unknown 2 years ago 2 years ago