Перейти к содержимому
Noroxi

Записи networktocode

17 опубликованных записей вендора networktocode.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
1
С записью об исправлении
100 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

17 записей
  • CVE-2023-25657
    39Наблюдать

    Remote code execution in Jinja2 template rendering in Nautobot

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    networktocode · nautobot21 февр. 2023 г.

  • CVE-2026-44797
    34Наблюдать

    Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    networktocode · nautobot28 мая 2026 г.

  • CVE-2026-44798
    28Наблюдать

    Nautobot: GitRepository.current_head field should not be writable through REST API

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    networktocode · nautobot28 мая 2026 г.

  • CVE-2026-44796
    26Наблюдать

    Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    networktocode · nautobot28 мая 2026 г.

  • CVE-2023-46128
    26Наблюдать

    Exposure of hashed user passwords via REST API in Nautobot

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    networktocode · nautobot25 окт. 2023 г.

  • CVE-2024-36112
    26Наблюдать

    Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    networktocode · nautobot28 мая 2024 г.

  • CVE-2025-49143
    25Наблюдать

    Nautobot may allows uploaded media files to be accessible without authentication

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    networktocode · nautobot10 июн. 2025 г.

  • CVE-2024-32979
    24Наблюдать

    Reflected Cross-site Scripting potential in all object list views in Nautobot

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    networktocode · nautobot1 мая 2024 г.

  • CVE-2025-49142
    24Наблюдать

    Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating

    СредняяCVSS 6,0Эксплойта нетEPSS 0 %

    networktocode · nautobot10 июн. 2025 г.

  • CVE-2023-50263
    21Наблюдать

    Nautobot allows unauthenticated db-file-storage views

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    networktocode · nautobot12 дек. 2023 г.

  • CVE-2024-29199
    21Наблюдать

    Unauthenticated views may expose information to anonymous users

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    networktocode · nautobot25 мар. 2024 г.

  • CVE-2023-48705
    21Наблюдать

    nautobot has XSS potential in custom links, job buttons, and computed fields

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    networktocode · nautobot22 нояб. 2023 г.

  • CVE-2024-23345
    21Наблюдать

    Nautobot has XSS potential in rendered Markdown fields

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    networktocode · nautobot22 янв. 2024 г.

  • CVE-2026-44794
    21Наблюдать

    Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    networktocode · nautobot28 мая 2026 г.

  • CVE-2024-34707
    19Наблюдать

    Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

    СредняяCVSS 4,8Эксплойта нетEPSS 1 %

    networktocode · nautobot14 мая 2024 г.

  • CVE-2023-51649
    17Наблюдать

    Nautobot missing object-level permissions enforcement when running Job Buttons

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    networktocode · nautobot22 дек. 2023 г.

  • CVE-2026-34203
    17Наблюдать

    Nautobot: Management of users via REST API does not apply configured password validators

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    networktocode · nautobot31 мар. 2026 г.