Nexus Repository
16 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Nexus Repository, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
Nexus Repository CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 2 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 3 |
| 2026-05 | 2 |
| 2026-06 | 1 |
| 2026-07 | 1 |
| 2026-08 | 1 |
| 2026-09 | 0 |
Severity
How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High5
- Medium5
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Nexus Repository.
- CVE-2026-17593Nexus Repository - Arbitrary Class Instantiation via Unsafe Realm Configuration7.2
- CVE-2026-7494Nexus Repository - SSRF in SSL Certificate Retrieval5.0
- CVE-2026-10748Nexus Repository 3 - Remote Code Execution via License Deserialization7.2
- CVE-2026-7308Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page5.4
- CVE-2026-3048Nexus Repository 3 - Improper LDAP Referral Handling3.8
- CVE-2026-5189Nexus Repository 3 - Hardcoded Credential in Internal Database Component9.8
- CVE-2026-3199Nexus Repository 3 - Authenticated Remote Code Execution via Task Property Injection8.8
- CVE-2026-3438Nexus Repository 3 - Reflected Cross-Site Scripting (XSS) in ?describe Pages6.1
- CVE-2026-0600Nexus Repository 3 - Server-Side Request Forgery in Proxy Repository Configuration—
- CVE-2026-0601Nexus Repository 3 - Cross-Site Scripting—
- CVE-2025-13488Nexus Repository 3 - Stored Cross-Site Scripting (XSS)—
- CVE-2025-9868Nexus Repository 2 - SSRF Vulnerability in Remote Browser Plugin—
- CVE-2024-5082Nexus Repository 2 - Remote Code Execution7.6
- CVE-2024-5083Nexus Repository 2 - Stored XSS5.4
- CVE-2024-5764Nexus Repository 3 - Static hard-coded encryption passphrase used by default6.5
Product grouping is registry-driven, with AI assist and human review. How it works