← All vendors

sonatype

34 known vulnerabilities affecting sonatype products.

Products

nexus_repository_manager 34

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2021-40143 Medium 2.3% 8.2 Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header …
CVE-2020-15871 Medium 2.2% 8.8 Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Co…
CVE-2020-11753 Medium 1.7% 8.8 An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 …
CVE-2026-17593 Medium 0.8% 7.2 An account holding the nexus:settings:update permission in Nexus Repository 3 (o…
CVE-2026-3199 Medium 0.8% 8.8 A vulnerability in the task management component of Sonatype Nexus Repository ve…
CVE-2026-77124 Medium 0.6% 7.2 In affected versions of Nexus Repository 3, the script execution endpoint (POST …
CVE-2026-3329 Medium 0.6% 7.5 A remote unauthenticated attacker may be able to conduct credential-guessing att…
CVE-2026-5189 Medium 0.6% 9.8 CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager vers…
CVE-2026-17603 Medium 0.5% 8.8 Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool …
CVE-2026-14644 Medium 0.3% 7.2 Nexus Repository 3 contained a privilege escalation vulnerability in the REST pr…
CVE-2026-17599 Medium 0.3% 7.2 Nexus Repository 3 contained an endpoint used to change the administrator accoun…
CVE-2026-10748 Medium 0.3% 7.2 An authenticated user with the nx-licensing-create privilege can upload a specia…
CVE-2026-11403 Medium 0.3% 7.5 A vulnerability in Sonatype Nexus Repository Manager's format-specific API key g…
CVE-2026-17601 Medium 0.3% 7.2 A user holding a permission to update privilege definitions could modify a wildc…
CVE-2026-77125 Medium 0.3% 7.1 A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobs…
CVE-2026-14646 Medium 0.3% 7.7 Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF)…
CVE-2026-17600 Medium 0.2% 8.8 Sonatype Nexus Repository 3 did not immediately terminate a user's active login …
CVE-2021-29158 Low 0.8% 4.9 Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect…
CVE-2026-17594 Low 0.7% 4.9 Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect aut…
CVE-2020-15869 Low 0.7% 5.4 Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issu…
CVE-2020-15870 Low 0.7% 6.1 Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issu…
CVE-2026-3438 Low 0.6% 6.1 A reflected cross-site scripting vulnerability exists in Sonatype Nexus Reposito…
CVE-2026-77123 Low 0.5% 6.5 Nexus Repository 3 contains a sensitive information disclosure vulnerability in …
CVE-2026-7308 Low 0.4% 5.4 An authenticated user with upload permission to a hosted repository can store co…
CVE-2026-3048 Low 0.3% 3.8 An authenticated administrator who configures or tests LDAP connectivity in Sona…
CVE-2026-77122 Low 0.3% 4.3 An authorization flaw in the REST API repository details endpoint (GET /service/…
CVE-2026-10741 Low 0.3% 4.9 Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulner…
CVE-2026-14645 Low 0.3% 5.5 Nexus Repository 3 does not validate the destination of the "Webhook: Global" ca…
CVE-2026-17596 Low 0.2% 6.1 Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XS…
CVE-2026-17595 Low 0.2% 2.7 Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Select…
CVE-2026-17598 Low 0.2% 4.9 Sonatype Nexus Repository 3 did not properly filter internal configuration keys …
CVE-2026-17597 Low 0.2% 2.7 Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability i…
CVE-2026-14504 Low 0.2% 6.5 An authorization bypass in Nexus Repository 3's component upload API allowed a u…
CVE-2026-7494 Low 0.2% 5.0 Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the S…