Show filters
47 Total Results
Displaying 21-30 of 47
Sort by:
Attacker Value
Unknown

CVE-2020-15868

Disclosure Date: August 12, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2020-15870

Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2).
Attacker Value
Unknown

CVE-2020-15871

Disclosure Date: July 31, 2020 (last updated November 28, 2024)
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
Attacker Value
Unknown

CVE-2020-15869

Disclosure Date: July 31, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2).
Attacker Value
Unknown

CVE-2020-11415

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext.
Attacker Value
Unknown

CVE-2020-11753

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate privileges to create, modify, and execute scripting tasks without use of the UI or API. NOTE: in 3.22.0, scripting is disabled by default (making this not exploitable).
Attacker Value
Unknown

CVE-2020-11444

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
Attacker Value
Unknown

CVE-2020-10203

Disclosure Date: April 01, 2020 (last updated February 21, 2025)
Sonatype Nexus Repository before 3.21.2 allows XSS.
Attacker Value
Unknown

CVE-2019-16530

Disclosure Date: October 21, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
Attacker Value
Unknown

CVE-2019-15893

Disclosure Date: October 16, 2019 (last updated November 27, 2024)
Sonatype Nexus Repository Manager 2.x before 2.14.15 allows Remote Code Execution.