Semua CVE enam bulan terakhir, diperbarui setiap hari.
Kerentanan yang sudah dipublikasikan, langsung dari National Vulnerability Database, lengkap dengan tingkat keparahan, kelas CWE, dan produk terdampak. Cari, saring, dan lihat apa yang terbit hari ini.
- 303 dalam 24 jam terakhir
- 2.210 dalam 7 hari terakhir
- 58.432 dalam enam bulan terakhir
Sumber: NVD (National Vulnerability Database) · Diperbarui 24 Sep 2026
Menampilkan 5 dari 5
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without san
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom R
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attack
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen
CWE-76f5 nginx_ingress_controllerWhen NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serve
Temukan bug sebelum penyerang menemukannya.
Masuk dengan GitHub dan jalankan audit pertama Anda dalam waktu kurang dari satu menit. Paket gratis tidak memerlukan kartu kredit.