Cym1102 maintains a narrowly focused product line centered on NGINX WebUI, a web-based control interface for the widely deployed NGINX web server. Vulnerabilities in this product skew strongly toward critical severity and cluster around common web-application and deserialization weaknesses—including untrusted deserialization, code injection, path traversal, cross-site scripting, and certificate validation flaws—that reflect the product's exposure to untrusted input and its role in server configuration and management. Defenders should treat this vendor's disclosures with high priority given the severity profile and the breadth of deployments that depend on NGINX; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cym1102 over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3737CRITICAL A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of the file /adminPage/www/addOv | Apr 13, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-3740CRITICAL A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file /adminPage/conf/reload. The ma | Apr 13, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3739CRITICAL A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of | Apr 13, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-3738CRITICAL A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation | Apr 13, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-3736HIGH A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adminPage/main/ | Apr 13, 2024 | 7.5 | 22 | NO | NO |
CVE-2026-2145MEDIUM A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Inte | Feb 8, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cym1102.
Media articles that mention a CVE ID that affects a product developed by Cym1102 — matched by CVE ID, not by vendor name.