Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sonatype nexus repository manager 3 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2020-11753
An issue exists in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this no...
Sonatype Nexus Repository Manager 3 3.22.0
Sonatype Nexus Repository Manager 3 3.21.1
5.4
CVSSv3
CVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 allow XSS (issue 1 of 2).
Sonatype Nexus Repository Manager 3
6.1
CVSSv3
CVE-2020-15870
Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 allow XSS (Issue 2 of 2).
Sonatype Nexus Repository Manager 3
8.8
CVSSv3
CVE-2020-15871
Sonatype Nexus Repository Manager OSS/Pro version prior to 3.25.1 allows Remote Code Execution.
Sonatype Nexus Repository Manager 3
8.2
CVSSv3
CVE-2021-40143
Sonatype Nexus Repository 3.x up to and including 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
Sonatype Nexus Repository Manager 3
7.2
CVSSv3
CVE-2019-16530
Sonatype Nexus Repository Manager 2.x prior to 2.14.15 and 3.x prior to 3.19, and IQ Server prior to 72, has remote code execution.
Sonatype Nexus Repository Manager
Sonatype Nexus Iq Server
4.3
CVSSv3
CVE-2022-27907
Sonatype Nexus Repository Manager 3.x prior to 3.38.0 allows SSRF.
Sonatype Nexus Repository Manager
4.8
CVSSv3
CVE-2018-12100
Sonatype Nexus Repository Manager versions 3.x prior to 3.12.0 has XSS in multiple areas in the Administration UI.
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2021-42568
Sonatype Nexus Repository Manager 3.x up to and including 3.35.0 allows malicious users to access the SSL Certificates Loading function via a low-privileged account.
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2021-43293
Sonatype Nexus Repository Manager 3.x prior to 3.36.0 allows a remote authenticated malicious user to potentially perform network enumeration via Server Side Request Forgery (SSRF).
Sonatype Nexus Repository Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »