Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.70% | — | Sonatype Nexus Repository Manager | 30/3/2022 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.38.0 allows SSRF. | |
| Modificada | Alta (7.5) | 2.0% | — | Nexusphp | 30/3/2022 | 17/6/2026 | Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content. | |
| Modificada | Crítica (9.8) | 2.4% | — | Nexusphp | 30/3/2022 | 17/6/2026 | SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Crítica (9.8) | 2.0% | — | Nexusphp | 30/3/2022 | 17/6/2026 | SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter. | |
| Modificada | Media (4.3) | 0.73% | — | Sonatype Nexus Repository Manager | 17/3/2022 | 17/6/2026 | Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (4.3) | 0.87% | — | Sonatype Nexus Repository Manager | 4/11/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF). | |
| Modificada | Media (4.3) | 0.47% | — | Sonatype Nexus Repository Manager | 2/11/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged account. | |
| Analizada | Alta (8.2) | 2.3% | — | Sonatype Nexus Repository Manager | 7/9/2021 | 22/9/2026 | Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote attacker may disclose sensitive information or request external resources from a vulnerable instance. | |
| Modificada | Media (4.3) | 0.87% | — | Cisco Nexus Insights | 2/9/2021 | 17/6/2026 | A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-based access control (RBAC) filters are not applied to file… | |
| Modificada | Media (5.4) | 24% | 💥 PoC | Sonatype Nexus Repository Manager | 10/8/2021 | 17/6/2026 | Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML files to a repository could redirect users to Nexus Repository Manager’s pages with code modifications. | |
| Modificada | Media (4.3) | 3.7% | — | Sonatype Nexus Repository Manager | 18/6/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access. | |
| Modificada | Media (6.1) | 0.67% | — | Sonatype Nexus Repository Manager | 28/4/2021 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local account can create entities with crafted properties that, when viewed by an administrator, can execute arbitrary JavaScript in the context of the NXRM application. | |
| Modificada | Media (5.3) | 1.8% | — | Sonatype Nexus Repository Manager | 27/4/2021 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed). | |
| Analizada | Media (4.9) | 0.98% | — | Sonatype Nexus Repository Manager | 23/4/2021 | 22/9/2026 | Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control. | |
| Modificada | Media (6.5) | 1.5% | — | Sonatype Nexus Repository Manager | 17/12/2020 | 17/6/2026 | Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0. | |
| Modificada | Alta (8.6) | 2.6% | — | Sonatype Nexus Repository Manager | 12/10/2020 | 17/6/2026 | A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user running nxrm also has access to). | |
| Modificada | Media (5.4) | 1.4% | — | Cisco Nexus Data Broker | 8/10/2020 | 17/6/2026 | A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup files. An attacker could exploit this… | |
| Modificada | Media (4.9) | 0.99% | — | Sonatype Nexus | 25/8/2020 | 17/6/2026 | In Sonatype Nexus Repository 3.26.1, an S3 secret key can be exposed by an admin user. | |
| Modificada | Alta (7.5) | 18% | 💥 Exploit | Nexusdb | 21/8/2020 | 17/6/2026 | NexusQA NexusDB before 4.50.23 allows the reading of files via ../ directory traversal. | |
| Modificada | Alta (7.5) | 1.1% | — | Sonatype Nexus Repository Manager | 12/8/2020 | 17/6/2026 | Sonatype Nexus Repository Manager OSS/Pro before 3.26.0 has Incorrect Access Control. | |
| Analizada | Alta (8.8) | 2.2% | — | Sonatype Nexus Repository Manager | 31/7/2020 | 22/9/2026 | Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution. | |
| Analizada | Media (6.1) | 0.68% | — | Sonatype Nexus Repository Manager | 31/7/2020 | 22/9/2026 | Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (Issue 2 of 2). | |
| Analizada | Media (5.4) | 0.68% | — | Sonatype Nexus Repository Manager | 31/7/2020 | 22/9/2026 | Sonatype Nexus Repository Manager OSS/Pro versions before 3.25.1 allow XSS (issue 1 of 2). | |
| Modificada | Media (4.9) | 0.65% | — | Sonatype Nexus Repository Manager | 27/4/2020 | 17/6/2026 | An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in cleartext. |