Toutes les CVE des six derniers mois, mises à jour chaque jour.
Les vulnérabilités publiées, directement issues de la National Vulnerability Database, avec leur gravité, leur classe CWE et les produits concernés. Cherchez, filtrez et voyez ce qui est arrivé aujourd’hui.
- 299 publiées ces dernières 24 heures
- 2 206 ces 7 derniers jours
- 58 463 ces six derniers mois
Source : NVD (National Vulnerability Database) · Mis à jour le 24 sept. 2026
5 sur 5 affichées
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without san
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom R
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attack
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen
CWE-76f5 nginx_ingress_controllerWhen NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serve
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.