Known Vulnerabilities for Nginx Ui by Nginxui
Listed below are 10 of the newest known vulnerabilities associated with "Nginx Ui" by "Nginxui".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-44015 json | Nginx UI is a web user interface for the Nginx web server. In 2.3.4 and earlier, an authenticated user can perform Server-Sid... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-42268 json | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to ... | Not Provided | 2026-05-12 | 2026-05-12 |
| CVE-2026-42238 json | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint... | Not Provided | 2026-05-04 | 2026-05-05 |
| CVE-2026-42223 json | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/settings/... | Not Provided | 2026-05-04 | 2026-05-05 |
| CVE-2026-42222 json | Nginx UI is a web user interface for the Nginx web server. In version 2.3.5, an unauthenticated bootstrap takeover exists in ... | Not Provided | 2026-05-04 | 2026-05-06 |
| CVE-2026-42221 json | Nginx UI is a web user interface for the Nginx web server. From version 2.0.0 to before version 2.3.8, an unauthenticated net... | Not Provided | 2026-05-04 | 2026-05-05 |
| CVE-2026-42220 json | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /api/se... | Not Provided | 2026-05-04 | 2026-05-06 |
| CVE-2026-40575 json | OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust ... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2026-40487 json | Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticat... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-34830 json | Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path inter... | Not Provided | 2026-04-02 | 2026-04-02 |