Nginxui

Nginx Ui

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht Exploit
  • EPSS 0.01%
  • Veröffentlicht 30.03.2026 19:26:27
  • Zuletzt bearbeitet 01.04.2026 18:16:43

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration. This issue has b...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 30.03.2026 17:59:30
  • Zuletzt bearbeitet 01.04.2026 18:33:36

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversal sequences. When specially crafted paths are supplied, the backend resolves them to the base Nginx c...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 30.03.2026 17:59:19
  • Zuletzt bearbeitet 01.04.2026 18:45:46

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent re...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 30.03.2026 17:59:04
  • Zuletzt bearbeitet 02.04.2026 17:10:01

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in the logrotate configuration allows an authenticated user to cause a complete Denial of Service (DoS). By submitting a negative int...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 30.03.2026 17:58:54
  • Zuletzt bearbeitet 01.04.2026 18:21:15

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to access, modify, and delete resources belonging to...

Medienbericht Exploit
  • EPSS 0.06%
  • Veröffentlicht 30.03.2026 17:58:42
  • Zuletzt bearbeitet 16.04.2026 22:16:37

Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context Protocol) integration exposes two HTTP endpoints: /mcp and /mcp_message. While /mcp requires both IP whitelisting and authenticati...

Medienbericht Exploit
  • EPSS 4.19%
  • Veröffentlicht 05.03.2026 16:28:13
  • Zuletzt bearbeitet 10.03.2026 18:11:27

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.3, the /api/backup endpoint is accessible without authentication and discloses the encryption keys required to decrypt the backup in the X-Backup-Security response header...

Exploit
  • EPSS 0.52%
  • Veröffentlicht 21.10.2024 17:15:03
  • Zuletzt bearbeitet 07.11.2024 15:15:04

Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the ser...

  • EPSS 0.58%
  • Veröffentlicht 21.10.2024 17:15:03
  • Zuletzt bearbeitet 07.11.2024 14:57:17

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the...

Exploit
  • EPSS 57.71%
  • Veröffentlicht 21.10.2024 17:15:03
  • Zuletzt bearbeitet 06.11.2024 18:28:54

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-bet...