CVE Tools

Nexus Repository

16 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Nexus Repository, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.

Nexus Repository CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nexus Repository CVEs per month
MonthCVEs
2024-101
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-121
2026-012
2026-020
2026-030
2026-043
2026-052
2026-061
2026-071
2026-081
2026-090

Severity

How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical18%
  • High542%
  • Medium542%
  • Low18%

Latest CVEs

The 15 most recently published vulnerabilities affecting Nexus Repository.

  1. CVE-2026-17593Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration7.2
  2. CVE-2026-7494Nexus Repository - SSRF in SSL Certificate Retrieval5.0
  3. CVE-2026-10748Nexus Repository 3 - Remote Code Execution via License Deserialization7.2
  4. CVE-2026-7308Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page5.4
  5. CVE-2026-3048Nexus Repository 3 - Improper LDAP Referral Handling3.8
  6. CVE-2026-5189Nexus Repository 3 - Hardcoded Credential in Internal Database Component9.8
  7. CVE-2026-3199Nexus Repository 3 - Authenticated Remote Code Execution via Task Property Injection8.8
  8. CVE-2026-3438Nexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe Pages6.1
  9. CVE-2026-0600Nexus Repository 3 - Server-Side Request Forgery in Proxy Repository Configuration—
  10. CVE-2026-0601Nexus Repository 3 - Cross-Site Scripting—
  11. CVE-2025-13488Nexus Repository 3 - Stored Cross-Site Scripting (XSS)—
  12. CVE-2025-9868Nexus Repository 2 - SSRF Vulnerability in Remote Browser Plugin—
  13. CVE-2024-5082Nexus Repository 2 - Remote Code Execution7.6
  14. CVE-2024-5083Nexus Repository 2 - Stored XSS5.4
  15. CVE-2024-5764Nexus Repository 3 - Static hard-coded encryption passphrase used by default6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store