Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.40% | — | Sonatype Nexus Repository Manager | 11/5/2026 | 22/9/2026 | An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This could allow the… | |
| Analizada | Media (5.1) | 0.29% | — | Sonatype Nexus Repository Manager | 11/5/2026 | 22/9/2026 | An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server. | |
| Analizada | Crítica (9.2) | 0.62% | — | Sonatype Nexus Repository Manager | 15/4/2026 | 18/9/2026 | CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the… | |
| Analizada | Media (5.1) | 0.61% | — | Sonatype Nexus Repository Manager | 8/4/2026 | 18/9/2026 | A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction. | |
| Analizada | Crítica (9.4) | 0.77% | — | Sonatype Nexus Repository Manager | 8/4/2026 | 18/9/2026 | A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control. | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Repository Manager | 23/2/2026 | 17/6/2026 | Dell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution and escalation of privileges. | |
| Analizada | Alta (7.8) | 0.10% | — | Dell Repository Manager | 29/9/2025 | 17/6/2026 | Dell Repository Manager (DRM), versions 3.4.7 and 3.4.8, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (5.9) | 0.39% | 💥 PoC | Sonatype Nexus Repository Manager | 23/10/2024 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any secrets stored in the Nexus Repository configuration database (SMTP or HTTP proxy credentials, user tokens, tokens, among others). The affected versions relied on a static hard-coded… | |
| Analizada | Alta (7.8) | 0.13% | — | Dell Repository Manager | 21/8/2024 | 17/6/2026 | Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing… | |
| Analizada | Media (5.5) | 0.23% | — | Dell Repository Manager | 24/4/2024 | 17/6/2026 | Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem with the privileges of the running web… | |
| Analizada | Alta (7.8) | 0.24% | — | Dell Repository Manager | 24/4/2024 | 17/6/2026 | Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the privileges of the running web application. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Repository Manager | 16/11/2023 | 17/6/2026 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Repository Manager | 16/11/2023 | 17/6/2026 | Dell Repository Manager, 3.4.3 and prior, contains an Improper Access Control vulnerability in its installation module. A local low-privileged attacker could potentially exploit this vulnerability, leading to gaining escalated privileges. | |
| Modificada | Alta (7.8) | 0.23% | — | HPE Control Repository Manager | 24/6/2022 | 17/6/2026 | A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow local escalation of privilege. HPE has made the following software update to resolve the vulnerability in HPE Version Control Repository Manager installer 7.6.14.0. | |
| Modificada | Alta (7.8) | 0.20% | — | Dell EMC Repository Manager | 21/4/2022 | 17/6/2026 | Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application's database… | |
| Modificada | Media (4.3) | 0.70% | — | Sonatype Nexus Repository Manager | 30/3/2022 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF. | |
| Modificada | Media (4.3) | 0.73% | — | Sonatype Nexus Repository Manager | 17/3/2022 | 17/6/2026 | Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection. | |
| Modificada | Media (4.3) | 0.87% | — | Sonatype Nexus Repository Manager | 4/11/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). | |
| Modificada | Media (4.3) | 0.47% | — | Sonatype Nexus Repository Manager | 2/11/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account. | |
| Analizada | Alta (8.2) | 2.3% | — | Sonatype Nexus Repository Manager | 7/9/2021 | 22/9/2026 | Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance. | |
| Modificada | Media (5.4) | 24% | 💥 PoC | Sonatype Nexus Repository Manager | 10/8/2021 | 17/6/2026 | Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications. | |
| Modificada | Alta (8.8) | 0.21% | — | Dell EMC Repository Manager | 19/7/2021 | 17/6/2026 | Dell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in a plain text in a local database. A local authenticated malicious user with access to the local file system may use the exposed password to access the with privileges of the… | |
| Modificada | Media (4.3) | 3.7% | — | Sonatype Nexus Repository Manager | 18/6/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access. | |
| Modificada | Media (6.1) | 0.67% | — | Sonatype Nexus Repository Manager | 28/4/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application. | |
| Modificada | Media (5.3) | 1.8% | — | Sonatype Nexus Repository Manager | 27/4/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed). |