networktocode records
17 published records for vendor networktocode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-400 Uncontrolled Resource Consumption1
- CWE-471 Modification of Assumed-Immutable Data (MAID)1
- CWE-521 Weak Password Requirements1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-25657No exploit | Remote code execution in Jinja2 template rendering in Nautobotnetworktocode · nautobot · CWE-94 | Critical9.8 | — | 1.5% | Feb 21, 2023 |
34Monitor | CVE-2026-44797No exploit | Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)networktocode · nautobot · CWE-918 | High8.5 | — | 0.4% | May 28, 2026 |
28Monitor | CVE-2026-44798No exploit | Nautobot: GitRepository.current_head field should not be writable through REST APInetworktocode · nautobot · CWE-471 | High7.1 | — | 0.5% | May 28, 2026 |
26Monitor | CVE-2026-44796No exploit | Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)networktocode · nautobot · CWE-400 | Medium6.5 | — | 0.6% | May 28, 2026 |
26Monitor | CVE-2023-46128No exploit | Exposure of hashed user passwords via REST API in Nautobotnetworktocode · nautobot · CWE-200 | Medium6.5 | — | 0.5% | Oct 25, 2023 |
26Monitor | CVE-2024-36112No exploit | Nautobot dynamic-group-members doesn't enforce permission restrictions on member objectsnetworktocode · nautobot · CWE-280 | Medium6.5 | — | 0.4% | May 28, 2024 |
25Monitor | CVE-2025-49143No exploit | Nautobot may allows uploaded media files to be accessible without authenticationnetworktocode · nautobot · CWE-200 | Medium6.3 | — | 0.4% | Jun 10, 2025 |
24Monitor | CVE-2024-32979No exploit | Reflected Cross-site Scripting potential in all object list views in Nautobotnetworktocode · nautobot · CWE-79 | Medium6.1 | — | 0.5% | May 1, 2024 |
24Monitor | CVE-2025-49142No exploit | Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templatingnetworktocode · nautobot · CWE-1336 | Medium6.0 | — | 0.4% | Jun 10, 2025 |
21Monitor | CVE-2023-50263No exploit | Nautobot allows unauthenticated db-file-storage viewsnetworktocode · nautobot · CWE-200 | Medium5.3 | — | 0.8% | Dec 12, 2023 |
21Monitor | CVE-2024-29199No exploit | Unauthenticated views may expose information to anonymous usersnetworktocode · nautobot · CWE-200 | Medium5.3 | — | 0.6% | Mar 25, 2024 |
21Monitor | CVE-2023-48705No exploit | nautobot has XSS potential in custom links, job buttons, and computed fieldsnetworktocode · nautobot · CWE-79 | Medium5.4 | — | 0.5% | Nov 22, 2023 |
21Monitor | CVE-2024-23345No exploit | Nautobot has XSS potential in rendered Markdown fieldsnetworktocode · nautobot · CWE-79 | Medium5.4 | — | 0.4% | Jan 22, 2024 |
21Monitor | CVE-2026-44794No exploit | Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to referencenetworktocode · nautobot · CWE-862 | Medium5.4 | — | 0.3% | May 28, 2026 |
19Monitor | CVE-2024-34707No exploit | Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pagesnetworktocode · nautobot · CWE-79 | Medium4.8 | — | 0.6% | May 14, 2024 |
17Monitor | CVE-2023-51649No exploit | Nautobot missing object-level permissions enforcement when running Job Buttonsnetworktocode · nautobot · CWE-863 | Medium4.3 | — | 0.5% | Dec 22, 2023 |
17Monitor | CVE-2026-34203No exploit | Nautobot: Management of users via REST API does not apply configured password validatorsnetworktocode · nautobot · CWE-521 | Medium4.3 | — | 0.3% | Mar 31, 2026 |
- CVE-2023-2565739Monitor
Remote code execution in Jinja2 template rendering in Nautobot
CriticalCVSS 9.8No exploitEPSS 2%networktocode · nautobotFeb 21, 2023
- CVE-2026-4479734Monitor
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
HighCVSS 8.5No exploitEPSS 0%networktocode · nautobotMay 28, 2026
- CVE-2026-4479828Monitor
Nautobot: GitRepository.current_head field should not be writable through REST API
HighCVSS 7.1No exploitEPSS 0%networktocode · nautobotMay 28, 2026
- CVE-2026-4479626Monitor
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
MediumCVSS 6.5No exploitEPSS 1%networktocode · nautobotMay 28, 2026
- CVE-2023-4612826Monitor
Exposure of hashed user passwords via REST API in Nautobot
MediumCVSS 6.5No exploitEPSS 1%networktocode · nautobotOct 25, 2023
- CVE-2024-3611226Monitor
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
MediumCVSS 6.5No exploitEPSS 0%networktocode · nautobotMay 28, 2024
- CVE-2025-4914325Monitor
Nautobot may allows uploaded media files to be accessible without authentication
MediumCVSS 6.3No exploitEPSS 0%networktocode · nautobotJun 10, 2025
- CVE-2024-3297924Monitor
Reflected Cross-site Scripting potential in all object list views in Nautobot
MediumCVSS 6.1No exploitEPSS 0%networktocode · nautobotMay 1, 2024
- CVE-2025-4914224Monitor
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
MediumCVSS 6.0No exploitEPSS 0%networktocode · nautobotJun 10, 2025
- CVE-2023-5026321Monitor
Nautobot allows unauthenticated db-file-storage views
MediumCVSS 5.3No exploitEPSS 1%networktocode · nautobotDec 12, 2023
- CVE-2024-2919921Monitor
Unauthenticated views may expose information to anonymous users
MediumCVSS 5.3No exploitEPSS 1%networktocode · nautobotMar 25, 2024
- CVE-2023-4870521Monitor
nautobot has XSS potential in custom links, job buttons, and computed fields
MediumCVSS 5.4No exploitEPSS 1%networktocode · nautobotNov 22, 2023
- CVE-2024-2334521Monitor
Nautobot has XSS potential in rendered Markdown fields
MediumCVSS 5.4No exploitEPSS 0%networktocode · nautobotJan 22, 2024
- CVE-2026-4479421Monitor
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
MediumCVSS 5.4No exploitEPSS 0%networktocode · nautobotMay 28, 2026
- CVE-2024-3470719Monitor
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
MediumCVSS 4.8No exploitEPSS 1%networktocode · nautobotMay 14, 2024
- CVE-2023-5164917Monitor
Nautobot missing object-level permissions enforcement when running Job Buttons
MediumCVSS 4.3No exploitEPSS 0%networktocode · nautobotDec 22, 2023
- CVE-2026-3420317Monitor
Nautobot: Management of users via REST API does not apply configured password validators
MediumCVSS 4.3No exploitEPSS 0%networktocode · nautobotMar 31, 2026