VendorsSonatypenexusany version
Vulnerabilities

Sonatype Nexus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-10199
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
Published 2020-04-01 · Analyzed
9.0KEV2 PoCEPSS 0.991
CVE-2020-10204
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
Published 2020-04-01 · Modified
9.0EPSS 0.382
CVE-2020-11444
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Published 2020-04-02 · Modified
8.8EPSS 0.085
CVE-2014-9389
Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.
Published 2015-01-05 · Modified
7.5EPSS 0.019
CVE-2020-24622
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
Published 2020-08-25 · Modified
4.9EPSS 0.010
CVE-2020-10203
Sonatype Nexus Repository before 3.21.2 allows XSS.
Published 2020-04-01 · Modified
4.8EPSS 0.009