Son altı ayın tüm CVE kayıtları, her gün güncellenir.
Ulusal Güvenlik Açığı Veritabanı’ndan doğrudan gelen yayımlanmış açıklar; önem derecesi, CWE sınıfı ve etkilenen ürünlerle. Arayın, filtreleyin, bugün ne çıktığını görün.
- Son 24 saatte 162 kayıt
- Son 7 günde 2.171 kayıt
- Son altı ayda 58.432 kayıt
Kaynak: NVD (Ulusal Güvenlik Açığı Veritabanı) · Güncellenme: 24 Eyl 2026
5 kayıttan 5 tanesi gösteriliyor
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without san
Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom R
DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attack
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the gen
CWE-76f5 nginx_ingress_controllerWhen NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serve
Açığı bir saldırgandan önce siz bulun.
GitHub ile giriş yapın ve ilk denetiminizi bir dakikadan kısa sürede başlatın. Ücretsiz plan için kredi kartı gerekmez.