sonatype / nexus_repository_manager
34 known vulnerabilities in sonatype nexus_repository_manager.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40143 | Medium | 2.3% | 8.2 | Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header … | |
| CVE-2020-15871 | Medium | 2.2% | 8.8 | Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Co… | |
| CVE-2020-11753 | Medium | 1.7% | 8.8 | An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 … | |
| CVE-2026-17593 | Medium | 0.8% | 7.2 | An account holding the nexus:settings:update permission in Nexus Repository 3 (o… | |
| CVE-2026-3199 | Medium | 0.8% | 8.8 | A vulnerability in the task management component of Sonatype Nexus Repository ve… | |
| CVE-2026-77124 | Medium | 0.6% | 7.2 | In affected versions of Nexus Repository 3, the script execution endpoint (POST … | |
| CVE-2026-3329 | Medium | 0.6% | 7.5 | A remote unauthenticated attacker may be able to conduct credential-guessing att… | |
| CVE-2026-5189 | Medium | 0.6% | 9.8 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager vers… | |
| CVE-2026-17603 | Medium | 0.5% | 8.8 | Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool … | |
| CVE-2026-14644 | Medium | 0.3% | 7.2 | Nexus Repository 3 contained a privilege escalation vulnerability in the REST pr… | |
| CVE-2026-17599 | Medium | 0.3% | 7.2 | Nexus Repository 3 contained an endpoint used to change the administrator accoun… | |
| CVE-2026-10748 | Medium | 0.3% | 7.2 | An authenticated user with the nx-licensing-create privilege can upload a specia… | |
| CVE-2026-11403 | Medium | 0.3% | 7.5 | A vulnerability in Sonatype Nexus Repository Manager's format-specific API key g… | |
| CVE-2026-17601 | Medium | 0.3% | 7.2 | A user holding a permission to update privilege definitions could modify a wildc… | |
| CVE-2026-77125 | Medium | 0.3% | 7.1 | A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobs… | |
| CVE-2026-14646 | Medium | 0.3% | 7.7 | Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF)… | |
| CVE-2026-17600 | Medium | 0.2% | 8.8 | Sonatype Nexus Repository 3 did not immediately terminate a user's active login … | |
| CVE-2021-29158 | Low | 0.8% | 4.9 | Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect… | |
| CVE-2026-17594 | Low | 0.7% | 4.9 | Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect aut… | |
| CVE-2020-15869 | Low | 0.7% | 5.4 | Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issu… | |
| CVE-2020-15870 | Low | 0.7% | 6.1 | Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issu… | |
| CVE-2026-3438 | Low | 0.6% | 6.1 | A reflected cross-site scripting vulnerability exists in Sonatype Nexus Reposito… | |
| CVE-2026-77123 | Low | 0.5% | 6.5 | Nexus Repository 3 contains a sensitive information disclosure vulnerability in … | |
| CVE-2026-7308 | Low | 0.4% | 5.4 | An authenticated user with upload permission to a hosted repository can store co… | |
| CVE-2026-3048 | Low | 0.3% | 3.8 | An authenticated administrator who configures or tests LDAP connectivity in Sona… | |
| CVE-2026-77122 | Low | 0.3% | 4.3 | An authorization flaw in the REST API repository details endpoint (GET /service/… | |
| CVE-2026-10741 | Low | 0.3% | 4.9 | Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulner… | |
| CVE-2026-14645 | Low | 0.3% | 5.5 | Nexus Repository 3 does not validate the destination of the "Webhook: Global" ca… | |
| CVE-2026-17596 | Low | 0.2% | 6.1 | Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XS… | |
| CVE-2026-17595 | Low | 0.2% | 2.7 | Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Select… | |
| CVE-2026-17598 | Low | 0.2% | 4.9 | Sonatype Nexus Repository 3 did not properly filter internal configuration keys … | |
| CVE-2026-17597 | Low | 0.2% | 2.7 | Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability i… | |
| CVE-2026-14504 | Low | 0.2% | 6.5 | An authorization bypass in Nexus Repository 3's component upload API allowed a u… | |
| CVE-2026-7494 | Low | 0.2% | 5.0 | Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the S… |