VYPR
Vendor

Sonatype

Products
6
CVEs
78
Across products
100
Status
Private

Products

6

Recent CVEs

78
View all 78 CVEs →
  • CVE-2020-10199HigKEVApr 1, 2020
    risk 0.80cvss 8.8epss 0.99

    Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

  • CVE-2019-7238CriKEVMar 21, 2019
    risk 0.75cvss 9.8epss 0.77

    Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

  • CVE-2019-9629CriJul 8, 2019
    risk 0.64cvss 9.8epss 0.01

    Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

  • CVE-2017-17717CriDec 17, 2017
    risk 0.64cvss 9.8epss 0.01

    Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.

  • CVE-2026-3199CriApr 8, 2026
    risk 0.61cvss epss 0.00

    A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

  • CVE-2026-5189CriApr 15, 2026
    risk 0.60cvss epss 0.00

    CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process…

  • CVE-2024-6060CriJun 25, 2024
    risk 0.60cvss epss 0.00

    An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

  • CVE-2019-5475HigSep 3, 2019
    risk 0.59cvss 8.8epss 0.18

    The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

  • CVE-2026-17601HigAug 7, 2026
    risk 0.58cvss epss 0.00

    A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or…

  • CVE-2020-11444HigApr 2, 2020
    risk 0.58cvss 8.8epss 0.09

    Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

  • CVE-2026-17603HigAug 7, 2026
    risk 0.57cvss epss 0.00

    Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the…

  • CVE-2026-17600HigAug 7, 2026
    risk 0.57cvss epss 0.00

    Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these…

  • CVE-2026-3329HigJun 11, 2026
    risk 0.57cvss epss 0.00

    A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

  • CVE-2025-9868HigOct 8, 2025
    risk 0.57cvss epss 0.00

    Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.15.2 allows unauthenticated remote attackers to exfiltrate proxy repository credentials via crafted HTTP requests.

  • CVE-2020-15871HigJul 31, 2020
    risk 0.57cvss 8.8epss 0.02

    Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

  • CVE-2020-11753HigApr 20, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default…

  • CVE-2026-14644HigAug 7, 2026
    risk 0.56cvss epss 0.00

    Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw…

  • CVE-2026-10748HigJun 16, 2026
    risk 0.56cvss epss 0.00

    An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.

  • CVE-2020-15012HigOct 12, 2020
    risk 0.56cvss 8.6epss 0.03

    A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to).

  • CVE-2026-17594HigAug 7, 2026
    risk 0.53cvss epss 0.00

    Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could…