İçeriğe atla
Noroxi

Sonatype kayıtları

sonatype üreticisine ait 72 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
2 · %2,8
Silahlaştırılmış
2 · %2,8
Pre-auth RCE
5
Düzeltme kaydı olan
%50
Yayından KEV’e ortanca
788 gün

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

72 kayıt
  • Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %99

    sonatype · nexus1 Nis 2020

  • Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %77

    sonatype · nexus repository manager21 Mar 2019

  • CVE-2019-5475
    41Planlayın

    The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vuln

    YüksekCVSS 8,8Kavram kanıtıEPSS %18

    sonatype · nexus repository manager3 Eyl 2019

  • CVE-2020-10204
    39İzleyin

    Sonatype Nexus Repository before 3.21.2 allows Remote Code Execution.

    YüksekCVSS 7,2Kavram kanıtıEPSS %38

    sonatype · nexus1 Nis 2020

  • CVE-2019-9629
    39İzleyin

    Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).

    KritikCVSS 9,8İstismar yokEPSS %1

    sonatype · nexus repository manager8 Tem 2019

  • CVE-2017-17717
    39İzleyin

    Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature

    KritikCVSS 9,8İstismar yokEPSS %1

    sonatype · nexus repository manager17 Ara 2017

  • CVE-2020-11444
    38İzleyin

    Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

    YüksekCVSS 8,8Kavram kanıtıEPSS %9

    sonatype · nexus2 Nis 2020

  • CVE-2026-3199
    37İzleyin

    Nexus Repository 3 - Authenticated Remote Code Execution via Task Property Injection

    KritikCVSS 9,4İstismar yokEPSS %1

    sonatype · nexus repository manager8 Nis 2026

  • CVE-2020-15871
    36İzleyin

    Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.

    YüksekCVSS 8,8İstismar yokEPSS %2

    sonatype · nexus repository manager31 Tem 2020

  • CVE-2020-11753
    36İzleyin

    An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0.

    YüksekCVSS 8,8İstismar yokEPSS %2

    sonatype · nexus repository manager20 Nis 2020

  • CVE-2026-5189
    36İzleyin

    Nexus Repository 3 - Hardcoded Credential in Internal Database Component

    KritikCVSS 9,2İstismar yokEPSS %1

    sonatype · nexus repository manager15 Nis 2026

  • CVE-2020-15012
    35İzleyin

    A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19.

    YüksekCVSS 8,6İstismar yokEPSS %3

    sonatype · nexus repository manager12 Eki 2020

  • CVE-2026-17601
    35İzleyin

    Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator

    YüksekCVSS 8,9İstismar yokEPSS %0

    sonatype · nexus repository manager7 Ağu 2026

  • CVE-2026-3329
    34İzleyin

    Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts

    YüksekCVSS 8,7İstismar yokEPSS %1

    sonatype · nexus repository manager11 Haz 2026

  • CVE-2026-17603
    34İzleyin

    Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API

    YüksekCVSS 8,7İstismar yokEPSS %0

    sonatype · nexus repository manager7 Ağu 2026

  • CVE-2026-14644
    34İzleyin

    Nexus Repository 3 - Privilege Escalation

    YüksekCVSS 8,6İstismar yokEPSS %0

    sonatype · nexus repository manager7 Ağu 2026

  • CVE-2026-10748
    34İzleyin

    Nexus Repository 3 - Remote Code Execution via License Deserialization

    YüksekCVSS 8,6İstismar yokEPSS %0

    sonatype · nexus repository manager16 Haz 2026

  • CVE-2026-11403
    34İzleyin

    Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation

    YüksekCVSS 8,7İstismar yokEPSS %0

    sonatype · nexus repository manager14 Tem 2026

  • CVE-2026-17600
    34İzleyin

    Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation

    YüksekCVSS 8,7İstismar yokEPSS %0

    sonatype · nexus repository manager7 Ağu 2026

  • CVE-2021-40143
    33İzleyin

    Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection.

    YüksekCVSS 8,2İstismar yokEPSS %2

    sonatype · nexus repository manager7 Eyl 2021

  • CVE-2026-17594
    32İzleyin

    Nexus Repository 3 - Authorization Bypass in Repository Creation

    YüksekCVSS 8,2Kavram kanıtıEPSS %1

    sonatype · nexus repository manager7 Ağu 2026

  • CVE-2026-14504
    32İzleyin

    Nexus Repository 3 - Authorization Bypass in Component Upload API

    YüksekCVSS 8,2İstismar yokEPSS %0

    sonatype · nexus repository manager14 Tem 2026

  • CVE-2014-0792
    31İzleyin

    Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vecto

    YüksekCVSS 7,5İstismar yokEPSS %3

    sonatype · nexus17 Oca 2014

  • CVE-2014-2034
    31İzleyin

    Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown v

    YüksekCVSS 7,5İstismar yokEPSS %2

    sonatype · nexus31 Mar 2014

  • CVE-2014-9389
    31İzleyin

    Directory traversal vulnerability in Sonatype Nexus OSS and Pro before 2.11.1-01 allows remote attackers to read or write to arbitrary files

    YüksekCVSS 7,5İstismar yokEPSS %2

    sonatype · nexus5 Oca 2015