Skip to main content

Vendor/product archive

sonatype / nexus_repository_manager CVEs

Beta · best-effort

31 CVEs tagged to sonatype / nexus_repository_manager3 Critical, 10 High, 18 Medium, 0 Low, 0 Unrated.

CVE-2026-10741

Published Jun 17, 2026

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to d…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-3329

Published Jun 11, 2026

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-5764

Published Oct 23, 2024

Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository conf…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43293

Published Nov 4, 2021

Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42568

Published Nov 2, 2021

Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37152

Published Aug 10, 2021

Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users t…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34553

Published Jun 18, 2021

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29159

Published Apr 28, 2021

A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted pro…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30635

Published Apr 27, 2021

Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29436

Published Dec 17, 2020

Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15012

Published Oct 12, 2020

A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get acce…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11415

Published Apr 27, 2020

An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as config…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15588

Published Nov 1, 2019

There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using Comm…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5475

Published Sep 3, 2019

The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configurat…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9630

Published Jul 8, 2019

Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-9629

Published Jul 8, 2019

Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-7238

Published Mar 21, 2019

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
54.4
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2