← Back

Nexus

nexus

Vendor: Sonatype • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonatype
1Nexus
Nov 21, 2024
Aug 25, 2020
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.
1Sonatype
1Nexus
Nov 21, 2024
Apr 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
1Sonatype
1Nexus
Nov 21, 2024
Apr 1, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
1Sonatype
1Nexus
Nov 21, 2024
Apr 1, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Sonatype Nexus Repository before 3.21.2 allows XSS.
1Sonatype
1Nexus
Nov 7, 2025
Apr 1, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
1Sonatype
1Nexus
May 6, 2026
Jan 5, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.
1Sonatype
1Nexus
May 6, 2026
Apr 1, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."
1Sonatype
1Nexus
Apr 29, 2026
Jan 17, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.