sonatype nexus CVE Vulnerabilities (8)

CVEs: 8 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting sonatype nexus (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 18 of 8 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-24622 In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. [email protected] 4.9 0.27% 2020-08-25 2024-11-21
CVE-2020-11444 Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control. [email protected] 8.8 58.75% 2020-04-02 2024-11-21
CVE-2020-10204 Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution. [email protected] 7.2 55.84% 2020-04-01 2024-11-21
CVE-2020-10203 Sonatype Nexus Repository before 3.21.2 allows XSS. [email protected] 4.8 0.35% 2020-04-01 2024-11-21
CVE-2020-10199 KEV Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). [email protected] 8.8 94.38% 2020-04-01 2025-11-07
CVE-2014-9389 Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors. [email protected] 7.5 0.83% 2015-01-05 2026-05-06
CVE-2014-2034 Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path." [email protected] 7.5 0.98% 2014-04-01 2026-05-06
CVE-2014-0792 Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types. [email protected] 7.5 3.05% 2014-01-17 2026-04-29
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence