Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nexus repository manager vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2020-11753
An issue exists in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this no...
Sonatype Nexus Repository Manager 3 3.22.0
Sonatype Nexus Repository Manager 3 3.21.1
356
VMScore
CVE-2021-42568
Sonatype Nexus Repository Manager 3.x up to and including 3.35.0 allows malicious users to access the SSL Certificates Loading function via a low-privileged account.
Sonatype Nexus Repository Manager
802
VMScore
CVE-2019-15588
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capabili...
Sonatype Nexus Repository Manager
2 Github repositories
312
VMScore
CVE-2019-14469
In Nexus Repository Manager prior to 3.18.0, users with elevated privileges can create stored XSS.
Sonatype Nexus Repository Manager
383
VMScore
CVE-2021-43961
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
Sonatype Nexus Repository Manager
445
VMScore
CVE-2018-16620
Sonatype Nexus Repository Manager prior to 3.14 has Incorrect Access Control.
Sonatype Nexus Repository Manager
580
VMScore
CVE-2018-16621
Sonatype Nexus Repository Manager prior to 3.14 allows Java Expression Language Injection.
Sonatype Nexus Repository Manager
312
VMScore
CVE-2021-37152
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 prior to 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.
Sonatype Nexus Repository Manager
356
VMScore
CVE-2020-11415
An issue exists in Sonatype Nexus Repository Manager 2.x prior to 2.14.17 and 3.x prior to 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Sonatype Nexus Repository Manager
356
VMScore
CVE-2021-43293
Sonatype Nexus Repository Manager 3.x prior to 3.36.0 allows a remote authenticated malicious user to potentially perform network enumeration via Server Side Request Forgery (SSRF).
Sonatype Nexus Repository Manager
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
CVE-2012-1823
memory leak
CVE-2024-0627
CVE-2024-31402
privilege escalation
CVE-2024-36418
remote code execution
CVE-2024-27844
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »