Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nexus vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2021-34553
Sonatype Nexus Repository Manager 3.x prior to 3.31.0 allows a remote authenticated malicious user to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.
Sonatype Nexus Repository Manager
356
VMScore
CVE-2022-27907
Sonatype Nexus Repository Manager 3.x prior to 3.38.0 allows SSRF.
Sonatype Nexus Repository Manager
641
VMScore
CVE-2017-12301
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local malicious user to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to insufficient san...
Cisco Nx-os 7.0\\(3\\)i4\\(6\\)
Cisco Nx-os 8.1\\(0\\)bd\\(0.20\\)
Cisco Nx-os 8.1\\(0.70\\)s0
Cisco Nx-os 7.3\\(2\\)d1\\(0.21\\)
Cisco Nx-os 8.0\\(0.74\\)
Cisco Nx-os 8.0\\(1\\)
Cisco Nx-os 6.0\\(2\\)a8\\(6.213\\)
Cisco Nx-os 6.0\\(2\\)a8\\(3\\)
Cisco Nx-os 7.0\\(0\\)hsk\\(0.357\\)
570
VMScore
CVE-2021-40143
Sonatype Nexus Repository 3.x up to and including 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
Sonatype Nexus Repository Manager 3
383
VMScore
CVE-2020-15869
Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 allow XSS (issue 1 of 2).
Sonatype Nexus Repository Manager 3
383
VMScore
CVE-2020-15870
Sonatype Nexus Repository Manager OSS/Pro versions prior to 3.25.1 allow XSS (Issue 2 of 2).
Sonatype Nexus Repository Manager 3
605
VMScore
CVE-2020-15871
Sonatype Nexus Repository Manager OSS/Pro version prior to 3.25.1 allows Remote Code Execution.
Sonatype Nexus Repository Manager 3
NA
CVE-2023-40347
Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.14 and previous versions does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to.
Jenkins Maven Artifact Choicelistprovider \\(nexus\\)
356
VMScore
CVE-2018-1999030
An exposure of sensitive information vulnerability exists in Jenkins Maven Artifact ChoiceListProvider (Nexus) Plugin 1.3.1 and previous versions in ArtifactoryChoiceListProvider.java, NexusChoiceListProvider.java, Nexus3ChoiceListProvider.java that allows malicious users to capt...
Jenkins Maven Artifact Choicelistprovider \\(nexus\\)
668
VMScore
CVE-2005-4056
SQL injection vulnerability in search.php in PluggedOut Nexus 0.1 allows remote malicious users to execute arbitrary SQL commands via the (1) Location, (2) Last Name, and (3) First Name parameters.
Jonathan Beckett Pluggedout Nexus 0.1
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »