Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nexus repository manager vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2018-5307
Multiple cross-site scripting (XSS) vulnerabilities in Sonatype Nexus Repository Manager (aka NXRM) 2.x prior to 2.14.6 allow remote malicious users to inject arbitrary web script or HTML via (1) the repoId or (2) format parameter to service/siesta/healthcheck/healthCheckFileDeta...
Sonatype Nexus Repository Manager
5.3
CVSSv3
CVE-2021-30635
Sonatype Nexus Repository Manager 3.x prior to 3.30.1 allows a remote malicious user to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed).
Sonatype Nexus Repository Manager
7.2
CVSSv3
CVE-2019-15893
Sonatype Nexus Repository Manager 2.x prior to 2.14.15 allows Remote Code Execution.
Sonatype Nexus Repository Manager
9.8
CVSSv3
CVE-2019-9629
Sonatype Nexus Repository Manager prior to 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
Sonatype Nexus Repository Manager
6.1
CVSSv3
CVE-2018-16619
Sonatype Nexus Repository Manager prior to 3.14 allows XSS.
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2021-34553
Sonatype Nexus Repository Manager 3.x prior to 3.31.0 allows a remote authenticated malicious user to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Sonatype Nexus Repository Manager
4.3
CVSSv3
CVE-2022-27907
Sonatype Nexus Repository Manager 3.x prior to 3.38.0 allows SSRF.
Sonatype Nexus Repository Manager
7.5
CVSSv3
CVE-2020-15868
Sonatype Nexus Repository Manager OSS/Pro prior to 3.26.0 has Incorrect Access Control.
Sonatype Nexus Repository Manager
9.8
CVSSv3
CVE-2017-17717
Sonatype Nexus Repository Manager up to and including 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.
Sonatype Nexus Repository Manager
6.1
CVSSv3
CVE-2021-29159
A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x prior to 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of t...
Sonatype Nexus Repository Manager
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27802
template injection
CVE-2024-0044
code injection
CVE-2024-35474
CVE-2024-27857
CVE-2024-23251
CVE-2024-23692
physical
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »