Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)0.32%—Dell Repository ManagerAI16/9/202617/9/2026
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.1)0.29%—Sonatype Nexus Repository Manager2/9/202622/9/2026
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group…
AnalizadaAlta (7.5)0.72%—Sonatype Nexus Repository Manager2/9/202622/9/2026
In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permission could continue to run previously-created scripts even after an administrator set…
AnalizadaMedia (6)0.46%—Sonatype Nexus Repository Manager2/9/202622/9/2026
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus…
AnalizadaMedia (5.3)0.28%—Sonatype Nexus Repository Manager2/9/202622/9/2026
An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve metadata for member repositories on which it held no direct permission, by…
AnalizadaMedia (5.3)0.25%—Sonatype Nexus Repository Manager2/9/202629/9/2026
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository…
AnalizadaAlta (8.7)0.48%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection.…
AnalizadaAlta (8.9)0.29%—Sonatype Nexus Repository Manager7/8/202623/9/2026
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.
AnalizadaAlta (8.7)0.25%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing…
AnalizadaMedia (6.9)0.34%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding…
AnalizadaMedia (5.3)0.23%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the…
AnalizadaMedia (5.1)0.23%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network…
AnalizadaMedia (6.3)0.24%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status.…
AnalizadaMedia (5.3)0.23%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and…
AnalizadaAlta (8.2)0.74%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different,…
AnalizadaAlta (7.2)0.77%—Sonatype Nexus Repository Manager7/8/202622/9/2026
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because…
AnalizadaAlta (8.6)0.34%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.
AnalizadaMedia (4.9)0.26%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if…
AnalizadaMedia (5.1)0.26%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This…
AnalizadaMedia (5.3)0.17%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0…
AnalizadaAlta (8.2)0.22%—Sonatype Nexus Repository Manager14/7/202622/9/2026
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
AnalizadaAlta (8.7)0.32%—Sonatype Nexus Repository Manager14/7/202622/9/2026
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user…
AnalizadaMedia (5.9)0.27%—Sonatype Nexus Repository Manager17/6/202621/7/2026
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.
AnalizadaAlta (8.6)0.32%—Sonatype Nexus Repository Manager16/6/202622/9/2026
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
AnalizadaAlta (8.7)0.63%—Sonatype Nexus Repository Manager11/6/202621/7/2026
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.