Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nginx

First CVE: Nov 24, 2009Active for: 17 yearsTotal CVEs: 7

Nginx maintains a focused but widely embedded web server and application platform whose vulnerabilities, despite a narrow product portfolio, carry outsized significance due to the vendor's prominence in internet-facing infrastructure and reverse-proxy deployments. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code; recurring weakness classes including buffer-boundary issues, path traversal, and improper exception handling reflect the parsing and access-control challenges inherent to a high-performance HTTP handler. Defenders should prioritize Nginx advisories for internet-reachable instances and treat the web server tier as a consistent patching surface; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nginx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 24, 2009
16 years ago
Most Recent CVE
Aug 18, 2022
1,436 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-3898MEDIUM
Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to cre
Nov 24, 20094.933NOYES
CVE-2021-46461CRITICAL
njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.
Feb 14, 20229.831NONO
CVE-2022-35173HIGH
An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.
Aug 18, 20227.525NONO
CVE-2009-3896MEDIUM
src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attacke
Nov 24, 20095.020NONO
CVE-2022-30503MEDIUM
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_set_number at src/njs_value.h.
Jun 2, 20225.519NONO
CVE-2022-29779MEDIUM
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_value_own_enumerate at src/njs_value.c.
Jun 2, 20225.519NONO
CVE-2022-29780MEDIUM
Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_prototype_sort at src/njs_array.c.
Jun 2, 20225.516NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
71%
14%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (42.9%)
Network2 (28.6%)
Unknown2 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (71.4%)
High0 (0.0%)
Unknown2 (28.6%)
User Interaction
None5 (71.4%)
Unknown2 (28.6%)
Required0 (0.0%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None2 (28.6%)
Unknown2 (28.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nginx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nginx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nginx's Products

View all 2 CNAs →

Top CWEs