Skip to content
Noroxi

networktocode records

17 published records for vendor networktocode.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

17 records
  • Remote code execution in Jinja2 template rendering in Nautobot

    CriticalCVSS 9.8No exploitEPSS 2%

    networktocode · nautobotFeb 21, 2023

  • Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

    HighCVSS 8.5No exploitEPSS 0%

    networktocode · nautobotMay 28, 2026

  • Nautobot: GitRepository.current_head field should not be writable through REST API

    HighCVSS 7.1No exploitEPSS 0%

    networktocode · nautobotMay 28, 2026

  • Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

    MediumCVSS 6.5No exploitEPSS 1%

    networktocode · nautobotMay 28, 2026

  • Exposure of hashed user passwords via REST API in Nautobot

    MediumCVSS 6.5No exploitEPSS 1%

    networktocode · nautobotOct 25, 2023

  • Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects

    MediumCVSS 6.5No exploitEPSS 0%

    networktocode · nautobotMay 28, 2024

  • Nautobot may allows uploaded media files to be accessible without authentication

    MediumCVSS 6.3No exploitEPSS 0%

    networktocode · nautobotJun 10, 2025

  • Reflected Cross-site Scripting potential in all object list views in Nautobot

    MediumCVSS 6.1No exploitEPSS 0%

    networktocode · nautobotMay 1, 2024

  • Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating

    MediumCVSS 6.0No exploitEPSS 0%

    networktocode · nautobotJun 10, 2025

  • Nautobot allows unauthenticated db-file-storage views

    MediumCVSS 5.3No exploitEPSS 1%

    networktocode · nautobotDec 12, 2023

  • Unauthenticated views may expose information to anonymous users

    MediumCVSS 5.3No exploitEPSS 1%

    networktocode · nautobotMar 25, 2024

  • nautobot has XSS potential in custom links, job buttons, and computed fields

    MediumCVSS 5.4No exploitEPSS 1%

    networktocode · nautobotNov 22, 2023

  • Nautobot has XSS potential in rendered Markdown fields

    MediumCVSS 5.4No exploitEPSS 0%

    networktocode · nautobotJan 22, 2024

  • Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

    MediumCVSS 5.4No exploitEPSS 0%

    networktocode · nautobotMay 28, 2026

  • Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

    MediumCVSS 4.8No exploitEPSS 1%

    networktocode · nautobotMay 14, 2024

  • Nautobot missing object-level permissions enforcement when running Job Buttons

    MediumCVSS 4.3No exploitEPSS 0%

    networktocode · nautobotDec 22, 2023

  • Nautobot: Management of users via REST API does not apply configured password validators

    MediumCVSS 4.3No exploitEPSS 0%

    networktocode · nautobotMar 31, 2026