VendorsSonatypenexusall versions
Vulnerabilities

Sonatype Nexus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2020-10199
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Published 2020-04-01 · Analyzed
9.0KEV2 PoCEPSS 0.991
CVE-2020-10204
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Published 2020-04-01 · Modified
9.0EPSS 0.382
CVE-2020-11444
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Published 2020-04-02 · Modified
8.8EPSS 0.085
CVE-2014-0792
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.
Published 2014-01-17 · Modified
7.5EPSS 0.028
CVE-2014-2034
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."
Published 2014-04-01 · Modified
7.5EPSS 0.021
CVE-2014-9389
Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.
Published 2015-01-05 · Modified
7.5EPSS 0.019
CVE-2020-24622
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Published 2020-08-25 · Modified
4.9EPSS 0.010
CVE-2020-10203
Sonatype Nexus Repository before 3.21.2 allows XSS.
Published 2020-04-01 · Modified
4.8EPSS 0.009