- How many CVEs does Sonatype have?
- Sonatype has 64 published CVE records since 2014, including 17 in the last two years.
- How many Sonatype CVEs are in CISA KEV?
- Yes — 2 of Sonatype's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which Sonatype products have the most CVEs?
- The Sonatype products with the most published CVEs are Nexus Repository Manager, nexus-public, Nexus Repository, nexus, Nexus Repository Manager 3.
- What are the most common weakness types in Sonatype CVEs?
- Sonatype's CVEs most often map to these CWE weakness types: CWE-918 (Server-Side Request Forgery (SSRF)), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-502 (Deserialization of Untrusted Data).
- Are there public exploits for Sonatype vulnerabilities?
- Yes — 9 of Sonatype's CVEs have a known public exploit.
- How many critical Sonatype vulnerabilities are there?
- Sonatype has 5 critical and 25 high-severity CVEs.
- What is the average severity of Sonatype CVEs?
- The average CVSS base score across Sonatype's scored CVEs is 6.7.