Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2963▼ 120 respecto a la semana anterior
Críticas / altas1404▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.23% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and… | |
| Analizada | Alta (8.2) | 0.74% | 💥 Exploit | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different,… | |
| Analizada | Alta (7.2) | 0.77% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because… | |
| Analizada | Alta (8.6) | 0.34% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint. | |
| Analizada | Media (4.9) | 0.26% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if… | |
| Analizada | Media (5.1) | 0.26% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This… | |
| Analizada | Media (5.3) | 0.17% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0… | |
| Analizada | Alta (8.2) | 0.22% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check. | |
| Analizada | Alta (8.7) | 0.32% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user… | |
| Analizada | Media (5.9) | 0.27% | — | Sonatype Nexus Repository Manager | 17/6/2026 | 21/7/2026 | Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials. | |
| Analizada | Alta (8.6) | 0.32% | — | Sonatype Nexus Repository Manager | 16/6/2026 | 22/9/2026 | An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0. | |
| Analizada | Alta (8.7) | 0.63% | — | Sonatype Nexus Repository Manager | 11/6/2026 | 21/7/2026 | A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Osnexus Quantastor SDS ManagerAI | 4/6/2026 | 22/7/2026 | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password. | |
| Pendiente de análisis | Media (6.8) | 0.47% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAI | 20/5/2026 | 23/7/2026 | A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This… | |
| Analizada | Media (5.1) | 0.40% | — | Sonatype Nexus Repository Manager | 11/5/2026 | 22/9/2026 | An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the… | |
| Analizada | Media (5.1) | 0.29% | — | Sonatype Nexus Repository Manager | 11/5/2026 | 22/9/2026 | An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server. | |
| Analizada | Crítica (9.2) | 0.62% | — | Sonatype Nexus Repository Manager | 15/4/2026 | 18/9/2026 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the… | |
| Analizada | Media (5.1) | 0.61% | — | Sonatype Nexus Repository Manager | 8/4/2026 | 18/9/2026 | A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction. | |
| Analizada | Crítica (9.4) | 0.77% | — | Sonatype Nexus Repository Manager | 8/4/2026 | 18/9/2026 | A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control. | |
| Analizada | Media (4.9) | 0.49% | — | Cisco Nexus Dashboard InsightsCisco Nexus Dashboard | 1/4/2026 | 1/7/2026 | A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a… | |
| Analizada | Media (6.5) | 0.29% | — | Cisco Nexus Dashboard | 1/4/2026 | 8/7/2026 | A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authentication details are included in the encrypted backup files. An… | |
| En análisis | Media (6.1) | 0.24% | — | Cisco Nexus DashboardAICisco Nexus Dashboard InsightsAI | 1/4/2026 | 17/6/2026 | A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit… | |
| Analizada | Alta (7.5) | 0.19% | — | Nexusinterface | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2. | |
| Analizada | Alta (7.5) | 0.35% | — | Nexusinterface | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in Nexusoft NexusInterface v3.2.0-beta.2. | |
| Aplazada | Alta (7.4) | 0.16% | — | Cisco Nexus 3600AICisco Nexus 9500-rAI | 25/2/2026 | 17/6/2026 | A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. |