Vulnerability lookup
Which CVEs affect your Artifactory or Nexus Repository version?
NVD, the CVE Program record and the vendors' advisories each hold part of the answer, and the vendors state affected versions as lists of per-branch ranges a reader has to parse by hand. This lookup collects them into one page per version: every known CVE with its severity, whether NVD and the vendor each say your version is affected, the fix on your branch, and how far behind the latest release you are.
Check a version
Paste the version your server reports. Build suffixes such as -02 and a leading v are fine.
Browse by product
JFrog
JFrog Artifactory self-managed 7.x
- Versions with CVEs
- 352
- CVEs on record
- 63
- Latest
- 7.161.29
359 versions listed by JFrog, the latest released September 15, 2026. Artifactory 4, 5 and 6 are not covered.
Every Artifactory version →
Sonatype
Sonatype Nexus Repository 3.x (OSS, Community and Pro)
- Versions with CVEs
- 194
- CVEs on record
- 66
- Latest
- 3.96.2
194 versions listed by Sonatype, the latest released September 18, 2026. Nexus Repository 2 is not covered.
Every Nexus Repository version →
How the answer is built
Each CVE carries two verdicts, never merged: what NVD's exact CPE match for the version says, and what the vendor's own CVE record says. NVD has not analyzed every record (a CVE can be Deferred with no version configuration at all), and the vendor's list is the one that names the fix on each branch, so a page counts a CVE when either source says affected and shows both columns side by side.
Release dates, end-of-life status and the latest version come from the vendor's own release and end-of-life pages. A version the vendor never listed gets no page; the checker says so and points at the nearest known versions. Versions with no known CVE are listed on the product index without a page.
Sources: NVD (exact CPE match and the published configurations), the CVE Program record (the vendor's CNA entry with its affected and fixed versions), JFrog's security advisories, release notes and end-of-life page, Sonatype's security advisories, release notes and end-of-life page. Pulled September 18, 2026. Every CVE row links to its NVD record and to the vendor's advisory.
About this page and CloudRepo
CloudRepo is a managed artifact repository, so there is no Artifactory or Nexus server for you to patch. In over 10 years of operation, CloudRepo has experienced no known security breaches. This page is not a scan of your server: the data is NVD's and the vendor's, linked on every row, pulled on September 18, 2026.
Read next
Look up another version