Show filters
236 Total Results
Displaying 81-90 of 236
Sort by:
Attacker Value
Unknown

CVE-2022-27907

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF.
Attacker Value
Unknown

CVE-2020-24770

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Attacker Value
Unknown

CVE-2020-24769

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.
Attacker Value
Unknown

CVE-2020-24771

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
Attacker Value
Unknown

CVE-2021-43961

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
Attacker Value
Unknown

CVE-2021-43293

Disclosure Date: November 04, 2021 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).
Attacker Value
Unknown

CVE-2021-42568

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account.
Attacker Value
Unknown

CVE-2021-40143

Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance.
Attacker Value
Unknown

CVE-2021-34765

Disclosure Date: September 01, 2021 (last updated February 23, 2025)
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-based access control (RBAC) filters are not applied to file download actions. An attacker could exploit this vulnerability by logging in to the application and then navigating to the directory listing and download functions. A successful exploit could allow the attacker to download sensitive files that should be restricted, which could result in disclosure of sensitive information.
Attacker Value
Unknown

CVE-2021-37152

Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications.