| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-24513 | ingress-nginx auth-url protection bypass | Kubernetes | ingress-nginx | Low | 3.1 | 2026-02-03 22:17:17 | Deep Dive |
| CVE-2026-24512 | ingress-nginx auth-method nginx configuration injection | Kubernetes | ingress-nginx | High | 8.8 | 2026-02-03 22:17:09 | Deep Dive |
| CVE-2026-1580 | ingress-nginx auth-method nginx configuration injection | Kubernetes | ingress-nginx | High | 8.8 | 2026-02-03 22:16:47 | Deep Dive |
| CVE-2025-62126 | WordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Sensitive Data Exposure vulnerability | Razvan Stanga | Varnish/Nginx Proxy Caching | Medium | 5.3 | 2025-12-31 15:36:42 | Deep Dive |
| CVE-2025-14727 | NGINX Ingress Controller vulnerability | F5 | NGINX Ingress Controller | High | 8.3 | 2025-12-17 15:48:22 | Deep Dive |
| CVE-2025-12014 | NGINX Cache Optimizer <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Dynamic Caching Exclusion Update | getclouder | NGINX Cache Optimizer | Medium | 4.3 | 2025-10-24 08:24:01 | Deep Dive |
| CVE-2025-58474 | BIG-IP Advanced WAF and ASM and NGINX App Protect DNS lookup vulnerability | F5 | BIG-IP | Medium | 5.3 | 2025-10-15 13:55:43 | Deep Dive |
| CVE-2025-48360 | WordPress Varnish/Nginx Proxy Caching plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerability | Razvan Stanga | Varnish/Nginx Proxy Caching | Medium | 5.9 | 2025-08-28 12:37:09 | Deep Dive |
| CVE-2025-55740 | Default Credentials in nginx-defender Configuration Files | Anipaleja | nginx-defender | Medium | 6.5 | 2025-08-19 19:52:26 | Deep Dive |
| CVE-2025-53859 | NGINX ngx_mail_smtp_module vulnerability | F5 | NGINX Plus | Low | 3.7 | 2025-08-13 14:46:55 | Deep Dive |
| CVE-2025-6213 | Nginx Cache Purge Preload <= 2.1.1 - Authenticated (Administrator+) Remote Code Execution | psauxit | Nginx Cache Purge Preload | High | 7.2 | 2025-07-22 09:22:44 | Deep Dive |
| CVE-2025-24514 | ingress-nginx controller - configuration injection via unsanitized auth-url annotation | kubernetes | ingress-nginx | High | 8.8 | 2025-03-24 23:29:37 | Deep Dive |
| CVE-2025-24513 | ingress-nginx controller - auth secret file path traversal vulnerability | kubernetes | ingress-nginx | Medium | 4.8 | 2025-03-24 23:29:25 | Deep Dive |
| CVE-2025-1098 | ingress-nginx controller - configuration injection via unsanitized mirror annotations | kubernetes | ingress-nginx | High | 8.8 | 2025-03-24 23:29:16 | Deep Dive |
| CVE-2025-1097 | ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation | kubernetes | ingress-nginx | High | 8.8 | 2025-03-24 23:29:06 | Deep Dive |
| CVE-2025-1974 | ingress-nginx admission controller RCE escalation | kubernetes | ingress-nginx | Critical | 9.8 | 2025-03-24 23:28:49 | Deep Dive |
| CVE-2025-1695 | NGINX Unit Java Vulnerability | F5 | NGINX Unit | Medium | 5.3 | 2025-03-04 00:54:52 | Deep Dive |
| CVE-2025-23419 | TLS Session Resumption Vulnerability | F5 | NGINX Open Source | Medium | 4.3 | 2025-02-05 17:31:07 | Deep Dive |
| CVE-2025-23776 | WordPress Cache Sniper for Nginx plugin <= 1.0.4.2 - Broken Access Control vulnerability | ekaterir | Cache Sniper for Nginx | Medium | 4.3 | 2025-01-16 20:06:54 | Deep Dive |
| CVE-2024-56236 | WordPress Hestia Nginx Cache plugin <= 2.4.0 - Cross Site Request Forgery (CSRF) vulnerability | Juniper | Hestia Nginx Cache | Medium | 4.3 | 2025-01-02 12:01:14 | Deep Dive |