Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2025-50579 A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to improper… Nginx Proxy Manager Mitigation only Fix from $1,6002025-08-19 CRITICAL 9.8 CVE-2024-46256 A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate. Nginx Proxy Manager Patch available Fix from $2,3002024-09-27 MEDIUM 6.3 CVE-2024-46257 A Command injection vulnerability in requestLetsEncryptSslWithDnsChallenge in NginxProxyManager 2.11.3 allows an attacker to achieve remote code exec… Nginx Proxy Manager Patch available Fix from $1,6002024-09-27 HIGH 8.8 CVE-2024-39935 jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate managem… Nginx Proxy Manager 2.11.3+ Fix from $1,9502024-07-04 CRITICAL 9.8 CVE-2023-27224 An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file. Nginx Proxy Manager No fix yet Fix from $2,3002023-03-22 HIGH 8.8 CVE-2023-23596EPSS 15% jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an htpasswd file with crafted u… Nginx Proxy Manager after 2.9.19 Fix from $1,9502023-01-20 MEDIUM 5.5 CVE-2019-15517 jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. Nginx Proxy Manager 2.0.13+ Fix from $1,6002019-08-23