VendorsNginx UInginx_ui2.0.0
Vulnerabilities

Nginx UI Nginx Ui 2.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-49368
Unchecked logrotate settings lead to arbitrary command execution
Published 2024-10-21 · Analyzed
9.8EPSS 0.277
CVE-2024-23827
Nginx-UI arbitrary file write through the Import Certificate feature
Published 2024-01-29 · Modified
9.8EPSS 0.007
CVE-2024-22198
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
Published 2024-01-11 · Modified
8.8EPSS 0.041
CVE-2024-22197
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
Published 2024-01-11 · Modified
8.8EPSS 0.015
CVE-2024-23828
Nginx-UI authenticated RCE through injecting into the application config via CRLF
Published 2024-01-29 · Modified
8.8EPSS 0.011
CVE-2024-49366
Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written
Published 2024-10-21 · Analyzed
7.7EPSS 0.006
CVE-2024-49367
Nginx UI's log path can be controlled
Published 2024-10-21 · Analyzed
7.5EPSS 0.006
CVE-2024-22196
Authenticated (user role) SQL injection in `OrderAndPaginate` (GHSL-2023-270)
Published 2024-01-11 · Modified
7.0EPSS 0.006