Sonatype kayıtları
sonatype üreticisine ait 72 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %2,8
- Silahlaştırılmış
- 2 · %2,8
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- 788 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-863 Incorrect Authorization7
- CWE-918 Server-Side Request Forgery (SSRF)6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-502 Deserialization of Untrusted Data3
- CWE-862 Missing Authorization2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
72 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2020-10199Silahlaştırılmış | Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).sonatype · nexus · CWE-917 | Yüksek8,8 | KEV | %99,1 | 1 Nis 2020 |
92Hemen | CVE-2019-7238Silahlaştırılmış | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.sonatype · nexus repository manager | Kritik9,8 | KEV | %77,1 | 21 Mar 2019 |
41Planlayın | CVE-2019-5475Kavram kanıtı | The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnsonatype · nexus repository manager · CWE-78 | Yüksek8,8 | — | %18,4 | 3 Eyl 2019 |
39İzleyin | CVE-2020-10204Kavram kanıtı | Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.sonatype · nexus · CWE-20 | Yüksek7,2 | — | %38,2 | 1 Nis 2020 |
39İzleyin | CVE-2019-9629İstismar yok | Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).sonatype · nexus repository manager · CWE-287 | Kritik9,8 | — | %1,5 | 8 Tem 2019 |
39İzleyin | CVE-2017-17717İstismar yok | Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration featuresonatype · nexus repository manager · CWE-327 | Kritik9,8 | — | %0,7 | 17 Ara 2017 |
38İzleyin | CVE-2020-11444Kavram kanıtı | Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.sonatype · nexus · CWE-276 | Yüksek8,8 | — | %8,5 | 2 Nis 2020 |
37İzleyin | CVE-2026-3199İstismar yok | Nexus Repository 3 - Authenticated Remote Code Execution via Task Property Injectionsonatype · nexus repository manager · CWE-502 | Kritik9,4 | — | %0,8 | 8 Nis 2026 |
36İzleyin | CVE-2020-15871İstismar yok | Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.sonatype · nexus repository manager | Yüksek8,8 | — | %2,2 | 31 Tem 2020 |
36İzleyin | CVE-2020-11753İstismar yok | An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0.sonatype · nexus repository manager · CWE-863 | Yüksek8,8 | — | %1,7 | 20 Nis 2020 |
36İzleyin | CVE-2026-5189İstismar yok | Nexus Repository 3 - Hardcoded Credential in Internal Database Componentsonatype · nexus repository manager · CWE-798 | Kritik9,2 | — | %0,6 | 15 Nis 2026 |
35İzleyin | CVE-2020-15012İstismar yok | A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19.sonatype · nexus repository manager · CWE-22 | Yüksek8,6 | — | %2,6 | 12 Eki 2020 |
35İzleyin | CVE-2026-17601İstismar yok | Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administratorsonatype · nexus repository manager · CWE-862 | Yüksek8,9 | — | %0,3 | 7 Ağu 2026 |
34İzleyin | CVE-2026-3329İstismar yok | Nexus Repository Manager - Improper Restriction of Excessive Authentication Attemptssonatype · nexus repository manager · CWE-307 | Yüksek8,7 | — | %0,6 | 11 Haz 2026 |
34İzleyin | CVE-2026-17603İstismar yok | Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration APIsonatype · nexus repository manager · CWE-94 | Yüksek8,7 | — | %0,5 | 7 Ağu 2026 |
34İzleyin | CVE-2026-14644İstismar yok | Nexus Repository 3 - Privilege Escalationsonatype · nexus repository manager · CWE-843 | Yüksek8,6 | — | %0,3 | 7 Ağu 2026 |
34İzleyin | CVE-2026-10748İstismar yok | Nexus Repository 3 - Remote Code Execution via License Deserializationsonatype · nexus repository manager · CWE-502 | Yüksek8,6 | — | %0,3 | 16 Haz 2026 |
34İzleyin | CVE-2026-11403İstismar yok | Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generationsonatype · nexus repository manager · CWE-331 | Yüksek8,7 | — | %0,3 | 14 Tem 2026 |
34İzleyin | CVE-2026-17600İstismar yok | Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivationsonatype · nexus repository manager · CWE-613 | Yüksek8,7 | — | %0,2 | 7 Ağu 2026 |
33İzleyin | CVE-2021-40143İstismar yok | Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection.sonatype · nexus repository manager · CWE-74 | Yüksek8,2 | — | %2,3 | 7 Eyl 2021 |
32İzleyin | CVE-2026-17594Kavram kanıtı | Nexus Repository 3 - Authorization Bypass in Repository Creationsonatype · nexus repository manager · CWE-863 | Yüksek8,2 | — | %0,7 | 7 Ağu 2026 |
32İzleyin | CVE-2026-14504İstismar yok | Nexus Repository 3 - Authorization Bypass in Component Upload APIsonatype · nexus repository manager · CWE-862 | Yüksek8,2 | — | %0,2 | 14 Tem 2026 |
31İzleyin | CVE-2014-0792İstismar yok | Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectosonatype · nexus · CWE-94 | Yüksek7,5 | — | %3,0 | 17 Oca 2014 |
31İzleyin | CVE-2014-2034İstismar yok | Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vsonatype · nexus | Yüksek7,5 | — | %2,1 | 31 Mar 2014 |
31İzleyin | CVE-2014-9389İstismar yok | Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary filessonatype · nexus · CWE-22 | Yüksek7,5 | — | %1,9 | 5 Oca 2015 |
- CVE-2020-1019995Hemen
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99sonatype · nexus1 Nis 2020
- CVE-2019-723892Hemen
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %77sonatype · nexus repository manager21 Mar 2019
- CVE-2019-547541Planlayın
The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vuln
YüksekCVSS 8,8Kavram kanıtıEPSS %18sonatype · nexus repository manager3 Eyl 2019
- CVE-2020-1020439İzleyin
Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.
YüksekCVSS 7,2Kavram kanıtıEPSS %38sonatype · nexus1 Nis 2020
- CVE-2019-962939İzleyin
Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
KritikCVSS 9,8İstismar yokEPSS %1sonatype · nexus repository manager8 Tem 2019
- CVE-2017-1771739İzleyin
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature
KritikCVSS 9,8İstismar yokEPSS %1sonatype · nexus repository manager17 Ara 2017
- CVE-2020-1144438İzleyin
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
YüksekCVSS 8,8Kavram kanıtıEPSS %9sonatype · nexus2 Nis 2020
- CVE-2026-319937İzleyin
Nexus Repository 3 - Authenticated Remote Code Execution via Task Property Injection
KritikCVSS 9,4İstismar yokEPSS %1sonatype · nexus repository manager8 Nis 2026
- CVE-2020-1587136İzleyin
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
YüksekCVSS 8,8İstismar yokEPSS %2sonatype · nexus repository manager31 Tem 2020
- CVE-2020-1175336İzleyin
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0.
YüksekCVSS 8,8İstismar yokEPSS %2sonatype · nexus repository manager20 Nis 2020
- CVE-2026-518936İzleyin
Nexus Repository 3 - Hardcoded Credential in Internal Database Component
KritikCVSS 9,2İstismar yokEPSS %1sonatype · nexus repository manager15 Nis 2026
- CVE-2020-1501235İzleyin
A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19.
YüksekCVSS 8,6İstismar yokEPSS %3sonatype · nexus repository manager12 Eki 2020
- CVE-2026-1760135İzleyin
Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator
YüksekCVSS 8,9İstismar yokEPSS %0sonatype · nexus repository manager7 Ağu 2026
- CVE-2026-332934İzleyin
Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts
YüksekCVSS 8,7İstismar yokEPSS %1sonatype · nexus repository manager11 Haz 2026
- CVE-2026-1760334İzleyin
Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API
YüksekCVSS 8,7İstismar yokEPSS %0sonatype · nexus repository manager7 Ağu 2026
- CVE-2026-1464434İzleyin
Nexus Repository 3 - Privilege Escalation
YüksekCVSS 8,6İstismar yokEPSS %0sonatype · nexus repository manager7 Ağu 2026
- CVE-2026-1074834İzleyin
Nexus Repository 3 - Remote Code Execution via License Deserialization
YüksekCVSS 8,6İstismar yokEPSS %0sonatype · nexus repository manager16 Haz 2026
- CVE-2026-1140334İzleyin
Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
YüksekCVSS 8,7İstismar yokEPSS %0sonatype · nexus repository manager14 Tem 2026
- CVE-2026-1760034İzleyin
Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation
YüksekCVSS 8,7İstismar yokEPSS %0sonatype · nexus repository manager7 Ağu 2026
- CVE-2021-4014333İzleyin
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection.
YüksekCVSS 8,2İstismar yokEPSS %2sonatype · nexus repository manager7 Eyl 2021
- CVE-2026-1759432İzleyin
Nexus Repository 3 - Authorization Bypass in Repository Creation
YüksekCVSS 8,2Kavram kanıtıEPSS %1sonatype · nexus repository manager7 Ağu 2026
- CVE-2026-1450432İzleyin
Nexus Repository 3 - Authorization Bypass in Component Upload API
YüksekCVSS 8,2İstismar yokEPSS %0sonatype · nexus repository manager14 Tem 2026
- CVE-2014-079231İzleyin
Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vecto
YüksekCVSS 7,5İstismar yokEPSS %3sonatype · nexus17 Oca 2014
- CVE-2014-203431İzleyin
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown v
YüksekCVSS 7,5İstismar yokEPSS %2sonatype · nexus31 Mar 2014
- CVE-2014-938931İzleyin
Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files
YüksekCVSS 7,5İstismar yokEPSS %2sonatype · nexus5 Oca 2015