VYPR

Vendor CVEs

Sonatype

All CVEs

78 total · sorted by risk
  • CVE-2026-17598MedAug 7, 2026
    risk 0.34cvss epss 0.00

    Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a…

  • CVE-2026-17595MedAug 7, 2026
    risk 0.34cvss epss 0.00

    Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal…

  • CVE-2026-17597MedAug 7, 2026
    risk 0.33cvss epss 0.00

    Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the…

  • CVE-2026-7308MedMay 11, 2026
    risk 0.33cvss epss 0.00

    An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions…

  • CVE-2026-3048MedMay 11, 2026
    risk 0.33cvss epss 0.00

    An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

  • CVE-2026-3438MedApr 8, 2026
    risk 0.33cvss epss 0.00

    A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user…

  • CVE-2026-0601MedJan 14, 2026
    risk 0.33cvss epss 0.00

    A reflected cross-site scripting vulnerability exists in Nexus Repository 3 that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted request requiring user interaction.

  • CVE-2025-13488MedDec 4, 2025
    risk 0.33cvss epss 0.00

    Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS)…

  • CVE-2024-5083MedNov 14, 2024
    risk 0.33cvss epss 0.00

    A stored Cross-site Scripting vulnerability has been discovered in Sonatype Nexus Repository 2 This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.

  • CVE-2026-10741MedJun 17, 2026
    risk 0.32cvss 4.9epss 0.00

    Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.

  • CVE-2021-29158MedApr 23, 2021
    risk 0.32cvss 4.9epss 0.01

    Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.

  • CVE-2020-24622MedAug 25, 2020
    risk 0.32cvss 4.9epss 0.01

    In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.

  • CVE-2020-11415MedApr 27, 2020
    risk 0.32cvss 4.9epss 0.01

    An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.

  • CVE-2020-10203MedApr 1, 2020
    risk 0.31cvss 4.8epss 0.01

    Sonatype Nexus Repository before 3.21.2 allows XSS.

  • CVE-2018-12100MedJun 11, 2018
    risk 0.31cvss 4.8epss 0.01

    Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.

  • CVE-2022-27907MedMar 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.

  • CVE-2021-43961MedMar 17, 2022
    risk 0.28cvss 4.3epss 0.01

    Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.

  • CVE-2021-43293MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.01

    Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).

  • CVE-2021-42568MedNov 2, 2021
    risk 0.28cvss 4.3epss 0.00

    Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.

  • CVE-2021-34553MedJun 18, 2021
    risk 0.28cvss 4.3epss 0.04

    Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

  • CVE-2026-14646MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server…

  • CVE-2026-14645MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations…

  • CVE-2026-7494MedJul 14, 2026
    risk 0.00cvss epss 0.00

    Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts.…

  • CVE-2026-14504HigJul 14, 2026
    risk 0.00cvss epss 0.00

    An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

  • CVE-2026-11403HigJul 14, 2026
    risk 0.00cvss epss 0.00

    A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer…

  • CVE-2014-9389Jan 5, 2015
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.

  • CVE-2014-2034Apr 1, 2014
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."

  • CVE-2014-0792Jan 17, 2014
    risk 0.00cvss epss 0.03

    Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.

Page 2 of 2