Any serious vulnerability in NGINX will be big news since it is so widespread. CVE database shows some entries by searching for "nginx" but I looked at all 2022 entries and the only ones affecting NGINX itself are in NJX plugin so actually not affecting NGINX core functionality.
https://nginx.org/en/security_advisories.html shows one "medium severity" vulnerability in the last 4 years.