Vulnerability index

Browse CVEs

34 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nexus Repository Manager HIGH 7.5
CVE-2026-3329

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentic…

Fix: 3.93.0+
Fix from $1,950 2026-06-11
Nexus Repository Manager MEDIUM 6.5
CVE-2024-5764

Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets store…

Fix: 3.73.0+
Fix from $1,600 2024-10-23
Nexus Repository Manager 3 HIGH 8.2
CVE-2021-40143

Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may d…

Fix: 3.34.0+
Fix from $1,950 2021-09-07
Nexus Repository Manager MEDIUM 5.4
CVE-2021-37152EPSS 24%

Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a rep…

Fix: 3.33.0+
Fix from $1,600 2021-08-10
Nexus Repository Manager MEDIUM 6.1
CVE-2021-29159

A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can cr…

Fix: 3.30.1+
Fix from $1,600 2021-04-28
Nexus Repository Manager MEDIUM 5.3
CVE-2021-30635

Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder…

Fix: 3.30.1+
Fix from $1,600 2021-04-27
Nexus Repository Manager MEDIUM 6.5
CVE-2020-29436

Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of …

Fix: 3.29.0+
Fix from $1,600 2020-12-17
Nexus Repository Manager HIGH 8.6
CVE-2020-15012

A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse …

Fix: 2.14.19+
Fix from $1,950 2020-10-12
Nexus Repository Manager HIGH 7.5
CVE-2020-15868

Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.

Fix: 3.26.0+
Fix from $1,950 2020-08-12
Nexus Repository Manager 3 HIGH 8.8
CVE-2020-15871

Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

Fix: 3.25.1+
Fix from $1,950 2020-07-31
Nexus Repository Manager 3 MEDIUM 6.1
CVE-2020-15870

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).

Fix: 3.25.1+
Fix from $1,600 2020-07-31
Nexus Repository Manager 3 MEDIUM 5.4
CVE-2020-15869

Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).

Fix: 3.25.1+
Fix from $1,600 2020-07-31
Nexus Repository Manager 3 HIGH 8.8
CVE-2020-11753

An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to …

Patch available
Fix from $1,950 2020-04-20
Nexus HIGH 8.8
CVE-2020-11444EPSS 9%

Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

Fix: after 3.21.2
Fix from $1,950 2020-04-02
Nexus HIGH 8.8
CVE-2020-10199 KEVEPSS 99%

Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

Fix: 3.21.2+
Fix from $1,950 2020-04-01
Nexus HIGH 7.2
CVE-2020-10204EPSS 25%

Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

Fix: 3.21.2+
Fix from $1,950 2020-04-01
Nexus Repository Manager HIGH 7.2
CVE-2019-15588EPSS 6%

There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (…

Fix: after 2.14.14
Fix from $1,950 2019-11-01
Nexus Iq Server HIGH 7.2
CVE-2019-16530

Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.

Fix: after 72
Fix from $1,950 2019-10-21
Nexus Repository Manager HIGH 7.2
CVE-2019-15893

Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.

Fix: 2.14.15+
Fix from $1,950 2019-10-16
Nexus Repository Manager HIGH 8.8
CVE-2019-5475EPSS 18%

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable da…

Fix: after 2.14.9-01
Fix from $1,950 2019-09-03
Nexus Repository Manager MEDIUM 5.4
CVE-2019-14469

In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.

Fix: after 3.17.0
Fix from $1,600 2019-08-22
Nexus Repository Manager CRITICAL 9.8
CVE-2019-9629

Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

Fix: 3.17.0+
Fix from $2,300 2019-07-08
Nexus Repository Manager HIGH 7.5
CVE-2019-9630

Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and im…

Fix: 3.17.0+
Fix from $1,950 2019-07-08
Nexus Repository Manager MEDIUM 6.1
CVE-2019-11629

Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.

Fix: 2.14.13+
Fix from $1,600 2019-05-07
Nexus Repository Manager CRITICAL 9.8
CVE-2019-7238 KEVEPSS 77%

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Fix: 3.15.0+
Fix from $2,300 2019-03-21
Nexus Repository Manager HIGH 7.5
CVE-2018-16620

Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.

Fix: 3.14.0+
Fix from $1,950 2018-11-15
Nexus Repository Manager HIGH 7.2
CVE-2018-16621

Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

Fix: 3.14.0+
Fix from $1,950 2018-11-15
Nexus Repository Manager MEDIUM 6.1
CVE-2018-16619

Sonatype Nexus Repository Manager before 3.14 allows XSS.

Fix: 3.14.0+
Fix from $1,600 2018-11-15
Nexus Repository Manager MEDIUM 6.1
CVE-2018-5306

Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject a…

Fix: 3.8+
Fix from $1,600 2018-02-09
Nexus Repository Manager MEDIUM 6.1
CVE-2018-5307

Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to injec…

Fix: 2.14.6+
Fix from $1,600 2018-02-09