netmaker records
8 published records for vendor netmaker.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-321 Use of Hard-coded Cryptographic Key3
- CWE-285 Improper Authorization1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-404 Improper Resource Shutdown or Release1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-915 Improperly Controlled Modification of Dynamically-Determined Object Attributes1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-0664No exploit | Use of Hard-coded Cryptographic Key in gravitl/netmakernetmaker · netmaker · CWE-321 | Critical9.8 | — | 1.7% | Feb 18, 2022 |
35Monitor | CVE-2022-23650No exploit | Use of Hard-coded Cryptographic Key in Netmakernetmaker · netmaker · CWE-321 | High8.8 | — | 1.6% | Feb 18, 2022 |
35Monitor | CVE-2022-36110No exploit | Netmaker vulnerable to Insufficient Granularity of Access Controlnetmaker · netmaker · CWE-285 | High8.8 | — | 0.9% | Sep 9, 2022 |
35Monitor | CVE-2023-32079No exploit | Netmaker Privilige Escalation Vulnerabilitynetmaker · netmaker · CWE-915 | High8.8 | — | 0.9% | Aug 24, 2023 |
34Monitor | CVE-2026-29771No exploit | Netmaker: Denial of Service via Server Shutdown Endpointnetmaker · netmaker · CWE-404 | High8.7 | — | 0.4% | Mar 7, 2026 |
32Monitor | CVE-2026-38651No exploit | Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0.netmaker · netmaker · CWE-347 | High8.2 | — | 0.4% | Apr 28, 2026 |
31Monitor | CVE-2023-32077Proof of concept | Netmaker has Hardcoded DNS Secret Keynetmaker · netmaker · CWE-321 | High7.5 | — | 3.5% | Aug 24, 2023 |
30Monitor | CVE-2023-32078No exploit | Netmaker IDOR Vulnerability Allows User to Update Other User's Passwordnetmaker · netmaker · CWE-639 | High7.5 | — | 0.7% | Aug 24, 2023 |
- CVE-2022-066440Plan
Use of Hard-coded Cryptographic Key in gravitl/netmaker
CriticalCVSS 9.8No exploitEPSS 2%netmaker · netmakerFeb 18, 2022
- CVE-2022-2365035Monitor
Use of Hard-coded Cryptographic Key in Netmaker
HighCVSS 8.8No exploitEPSS 2%netmaker · netmakerFeb 18, 2022
- CVE-2022-3611035Monitor
Netmaker vulnerable to Insufficient Granularity of Access Control
HighCVSS 8.8No exploitEPSS 1%netmaker · netmakerSep 9, 2022
- CVE-2023-3207935Monitor
Netmaker Privilige Escalation Vulnerability
HighCVSS 8.8No exploitEPSS 1%netmaker · netmakerAug 24, 2023
- CVE-2026-2977134Monitor
Netmaker: Denial of Service via Server Shutdown Endpoint
HighCVSS 8.7No exploitEPSS 0%netmaker · netmakerMar 7, 2026
- CVE-2026-3865132Monitor
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0.
HighCVSS 8.2No exploitEPSS 0%netmaker · netmakerApr 28, 2026
- CVE-2023-3207731Monitor
Netmaker has Hardcoded DNS Secret Key
HighCVSS 7.5Proof of conceptEPSS 4%netmaker · netmakerAug 24, 2023
- CVE-2023-3207830Monitor
Netmaker IDOR Vulnerability Allows User to Update Other User's Password
HighCVSS 7.5No exploitEPSS 1%netmaker · netmakerAug 24, 2023