Nexus
This hub aggregates every CVE we track for Nexus, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
0
Critical
6
High
1
In CISA KEV
Severity distribution
HIGH6MEDIUM3
Monthly trend
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Nexus.
- CVE-2022-4974Freemius SDK <= 2.4.2 - Missing Authorization Checks6.3
- CVE-2020-24622In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user.4.9
- CVE-2020-11444Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.8.8
- CVE-2020-10199Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).KEV8.8
- CVE-2020-10204Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.7.2
- CVE-2020-10203Sonatype Nexus Repository before 3.21.2 allows XSS.4.8
- CVE-2014-9389Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files via unspecified vectors.7.5
- CVE-2014-2034Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."7.5
- CVE-2014-0792Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.7.5
Product normalization is registry-driven with AI assist and human review. How it works