Vulnerabilities
Last updated 36 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
0xJacky/nginx-ui /api/nodes Leaks Cluster Node Tokens and Allows Cross-Node Impersonation as initUser | High Risk 8.8 | 3 hours ago | 3 hours ago |
|
|
Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up | High Risk 8.8 | 3 hours ago | 3 hours ago |
|
|
Nginx UI: Node Secret Credential Exposure via URL Query Parameter | High Risk 8.8 | 3 hours ago | 3 hours ago |
|
|
Nginx-UI AuthRequired token cookie fallback enables CSRF against management APIs | High Risk 8.8 | 3 hours ago | 3 hours ago |
|
|
Nginx UI: Authentication bypass: password login does not enforce a passkey-only second factor (2FA bypass) | High Risk 8.1 | 3 hours ago | 3 hours ago |
|
|
Nginx UI: Self-upgrade runs an unsigned binary verified only by a same-origin digest → RCE via a compromised mirror or MITM | High Risk 7.5 | 3 hours ago | 3 hours ago |
|
|
Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied | High Risk 8.1 | 3 hours ago | 3 hours ago |
|
|
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse | High Risk 8.0 | 6 months ago | 29 days ago |
|
|
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation | Medium Risk 6.0 | 6 months ago | 29 days ago |
|
|
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover | Critical 9.8 | 6 months ago | 29 days ago |
|
|
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval | Medium Risk 6.0 | 6 months ago | 29 days ago |
|
|
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys | High Risk 8.8 | 6 months ago | 29 days ago |
|
|
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback | Medium Risk 6.5 | 5 months ago | 2 months ago |
|
|
nginx-ui Backup Restore Allows Tampering with Encrypted Backups | Critical 9.5 | 6 months ago | 3 months ago |
|
|
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270) | High Risk 7.0 | 2 years ago | 3 months ago |
|
|
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF | High Risk 8.8 | 2 years ago | 3 months ago |
|
|
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature | Critical 9.8 | 2 years ago | 3 months ago |
|
|
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268) | High Risk 7.1 | 2 years ago | 3 months ago |
|
|
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269) | High Risk 7.7 | 2 years ago | 3 months ago |
|
|
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover | High Risk 8.1 | 5 months ago | 3 months ago |
|
|
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens | High Risk 8.1 | 5 months ago | 3 months ago |
|
|
Nginx-UI Settings API Exposes Protected Secrets | Medium Risk 6.5 | 5 months ago | 3 months ago |
|
|
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services | High Risk 8.5 | 5 months ago | 3 months ago |
|
|
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim | High Risk 8.1 | 5 months ago | 3 months ago |
|
|
Nginx-UI: Disabled users retain full API access through previously issued bearer tokens in github.com/0xJacky/Nginx-UI | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI Settings API Exposes Protected Secrets in github.com/0xJacky/nginx-ui | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI has Server-Side Request Forgery (SSRF) via Cluster Proxy Middleware that Allows Access to Internal Services in github.com/0xJacky/Nginx-UI | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI: Unauthenticated first-boot instance claim via POST /api/install allows remote bootstrap takeover in github.com/0xJacky/nginx-ui | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI: Unauthenticated First-Run Installer Allows Remote Initial Admin Claim in github.com/0xJacky/Nginx-UI | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints | High Risk 8.1 | 5 months ago | 3 months ago |
|
|
Nginx-UI: Authenticated settings disclosure exposes node.secret and enables trusted-node authentication abuse, backup exfiltration, and restore-based nginx-ui state rollback in github.com/0xJacky/Nginx-UI | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI: Cross-Site WebSocket Hijacking (CSWSH) via missing origin validation on all WebSocket endpoints in github.com/0xJacky/Nginx-UI | Unknown | 3 months ago | 3 months ago |
|
|
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore | Critical 9.8 | 5 months ago | 3 months ago |
|
|
Nginx-UI is Vulnerable to Unauthenticated Remote Code Execution via Backup Restore in github.com/0xJacky/nginx-ui | Unknown | 3 months ago | 3 months ago |
|
|
nginx-UI has Unencrypted Storage of DNS API Tokens and ACME Private Keys in github.com/0xJacky/nginx-ui | Unknown | 6 months ago | 6 months ago |
|
|
nginx-ui's Unauthenticated MCP Endpoint Allows Remote Nginx Takeover in github.com/0xJacky/Nginx-UI | Unknown | 6 months ago | 6 months ago |
|
|
nginx-ui has Race Condition that Leads to Persistent Data Corruption and Service Collapse in github.com/0xJacky/Nginx-UI | Unknown | 6 months ago | 6 months ago |
|
|
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation in github.com/0xJacky/Nginx-UI | Unknown | 6 months ago | 6 months ago |
|
|
nginx-ui Backup Restore Allows Tampering with Encrypted Backups in github.com/0xJacky/Nginx-UI | Unknown | 6 months ago | 6 months ago |
|
|
nginx-ui Vulnerable to DoS via Negative Integer Input in Logrotate Interval in github.com/0xJacky/Nginx-UI | Unknown | 6 months ago | 6 months ago |
|
|
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure | Critical 9.8 | 7 months ago | 6 months ago |
|
|
Nginx-UI Vulnerable to Unauthenticated Backup Download with Encryption Key Disclosure in github.com/0xJacky/Nginx-UI | Unknown | 7 months ago | 6 months ago |
|
|
Nginx-UI vulnerable to authenticated RCE through injecting into the application config via CRLF in github.com/0xJacky/Nginx-UI | Unknown | 2 years ago | 2 years ago |
|
|
Nginx-UI vulnerable to arbitrary file write through the Import Certificate feature in github.com/0xJacky/Nginx-UI | Unknown | 2 years ago | 2 years ago |
|
|
Arbitrary command execution in github.com/0xJacky/Nginx-UI | Unknown | 2 years ago | 2 years ago |
|
|
SQL injection in github.com/0xJacky/Nginx-UI | Unknown | 2 years ago | 2 years ago |
|
|
Remote command execution in github.com/0xJacky/Nginx-UI | Unknown | 2 years ago | 2 years ago |
Page 1