Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-3329
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentic…
Nexus Repository Manager
3.93.0+
MEDIUM 6.5
CVE-2024-5764
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets store…
Nexus Repository Manager
3.73.0+
HIGH 8.2
CVE-2021-40143
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may d…
Nexus Repository Manager 3
3.34.0+
MEDIUM 5.4
CVE-2021-37152EPSS 24%
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a rep…
Nexus Repository Manager
3.33.0+
MEDIUM 6.1
CVE-2021-29159
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can cr…
Nexus Repository Manager
3.30.1+
MEDIUM 5.3
CVE-2021-30635
Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder…
Nexus Repository Manager
3.30.1+
MEDIUM 6.5
CVE-2020-29436
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of …
Nexus Repository Manager
3.29.0+
HIGH 8.6
CVE-2020-15012
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse …
Nexus Repository Manager
2.14.19+
HIGH 7.5
CVE-2020-15868
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
Nexus Repository Manager
3.26.0+
HIGH 8.8
CVE-2020-15871
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
Nexus Repository Manager 3
3.25.1+
MEDIUM 6.1
CVE-2020-15870
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
Nexus Repository Manager 3
3.25.1+
MEDIUM 5.4
CVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
Nexus Repository Manager 3
3.25.1+
HIGH 8.8
CVE-2020-11753
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to …
Nexus Repository Manager 3
Patch available
HIGH 8.8
CVE-2020-11444EPSS 9%
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Nexus
after 3.21.2
HIGH 8.8
CVE-2020-10199 KEVEPSS 99%
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Nexus
3.21.2+
HIGH 7.2
CVE-2020-10204EPSS 25%
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Nexus
3.21.2+
HIGH 7.2
CVE-2019-15588EPSS 6%
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (…
Nexus Repository Manager
after 2.14.14
HIGH 7.2
CVE-2019-16530
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Nexus Iq Server
after 72
HIGH 7.2
CVE-2019-15893
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.
Nexus Repository Manager
2.14.15+
HIGH 8.8
CVE-2019-5475EPSS 18%
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable da…
Nexus Repository Manager
after 2.14.9-01
MEDIUM 5.4
CVE-2019-14469
In Nexus Repository Manager before 3.18.0, users with elevated privileges can create stored XSS.
Nexus Repository Manager
after 3.17.0
CRITICAL 9.8
CVE-2019-9629
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
Nexus Repository Manager
3.17.0+
HIGH 7.5
CVE-2019-9630
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and im…
Nexus Repository Manager
3.17.0+
MEDIUM 6.1
CVE-2019-11629
Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
Nexus Repository Manager
2.14.13+
CRITICAL 9.8
CVE-2019-7238 KEVEPSS 77%
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
Nexus Repository Manager
3.15.0+
HIGH 7.5
CVE-2018-16620
Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.
Nexus Repository Manager
3.14.0+
HIGH 7.2
CVE-2018-16621
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
Nexus Repository Manager
3.14.0+
MEDIUM 6.1
CVE-2018-16619
Sonatype Nexus Repository Manager before 3.14 allows XSS.
Nexus Repository Manager
3.14.0+
MEDIUM 6.1
CVE-2018-5306
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 3.x before 3.8 allow remote attackers to inject a…
Nexus Repository Manager
3.8+
MEDIUM 6.1
CVE-2018-5307
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x before 2.14.6 allow remote attackers to injec…
Nexus Repository Manager
2.14.6+