Записи networktocode
17 опубликованных записей вендора networktocode.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-400 Uncontrolled Resource Consumption1
- CWE-471 Modification of Assumed-Immutable Data (MAID)1
- CWE-521 Weak Password Requirements1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
17 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2023-25657Эксплойта нет | Remote code execution in Jinja2 template rendering in Nautobotnetworktocode · nautobot · CWE-94 | Критическая9,8 | — | 1,5 % | 21 февр. 2023 г. |
34Наблюдать | CVE-2026-44797Эксплойта нет | Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)networktocode · nautobot · CWE-918 | Высокая8,5 | — | 0,4 % | 28 мая 2026 г. |
28Наблюдать | CVE-2026-44798Эксплойта нет | Nautobot: GitRepository.current_head field should not be writable through REST APInetworktocode · nautobot · CWE-471 | Высокая7,1 | — | 0,5 % | 28 мая 2026 г. |
26Наблюдать | CVE-2026-44796Эксплойта нет | Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)networktocode · nautobot · CWE-400 | Средняя6,5 | — | 0,6 % | 28 мая 2026 г. |
26Наблюдать | CVE-2023-46128Эксплойта нет | Exposure of hashed user passwords via REST API in Nautobotnetworktocode · nautobot · CWE-200 | Средняя6,5 | — | 0,5 % | 25 окт. 2023 г. |
26Наблюдать | CVE-2024-36112Эксплойта нет | Nautobot dynamic-group-members doesn't enforce permission restrictions on member objectsnetworktocode · nautobot · CWE-280 | Средняя6,5 | — | 0,4 % | 28 мая 2024 г. |
25Наблюдать | CVE-2025-49143Эксплойта нет | Nautobot may allows uploaded media files to be accessible without authenticationnetworktocode · nautobot · CWE-200 | Средняя6,3 | — | 0,4 % | 10 июн. 2025 г. |
24Наблюдать | CVE-2024-32979Эксплойта нет | Reflected Cross-site Scripting potential in all object list views in Nautobotnetworktocode · nautobot · CWE-79 | Средняя6,1 | — | 0,5 % | 1 мая 2024 г. |
24Наблюдать | CVE-2025-49142Эксплойта нет | Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templatingnetworktocode · nautobot · CWE-1336 | Средняя6,0 | — | 0,4 % | 10 июн. 2025 г. |
21Наблюдать | CVE-2023-50263Эксплойта нет | Nautobot allows unauthenticated db-file-storage viewsnetworktocode · nautobot · CWE-200 | Средняя5,3 | — | 0,8 % | 12 дек. 2023 г. |
21Наблюдать | CVE-2024-29199Эксплойта нет | Unauthenticated views may expose information to anonymous usersnetworktocode · nautobot · CWE-200 | Средняя5,3 | — | 0,6 % | 25 мар. 2024 г. |
21Наблюдать | CVE-2023-48705Эксплойта нет | nautobot has XSS potential in custom links, job buttons, and computed fieldsnetworktocode · nautobot · CWE-79 | Средняя5,4 | — | 0,5 % | 22 нояб. 2023 г. |
21Наблюдать | CVE-2024-23345Эксплойта нет | Nautobot has XSS potential in rendered Markdown fieldsnetworktocode · nautobot · CWE-79 | Средняя5,4 | — | 0,4 % | 22 янв. 2024 г. |
21Наблюдать | CVE-2026-44794Эксплойта нет | Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to referencenetworktocode · nautobot · CWE-862 | Средняя5,4 | — | 0,3 % | 28 мая 2026 г. |
19Наблюдать | CVE-2024-34707Эксплойта нет | Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pagesnetworktocode · nautobot · CWE-79 | Средняя4,8 | — | 0,6 % | 14 мая 2024 г. |
17Наблюдать | CVE-2023-51649Эксплойта нет | Nautobot missing object-level permissions enforcement when running Job Buttonsnetworktocode · nautobot · CWE-863 | Средняя4,3 | — | 0,5 % | 22 дек. 2023 г. |
17Наблюдать | CVE-2026-34203Эксплойта нет | Nautobot: Management of users via REST API does not apply configured password validatorsnetworktocode · nautobot · CWE-521 | Средняя4,3 | — | 0,3 % | 31 мар. 2026 г. |
- CVE-2023-2565739Наблюдать
Remote code execution in Jinja2 template rendering in Nautobot
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %networktocode · nautobot21 февр. 2023 г.
- CVE-2026-4479734Наблюдать
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %networktocode · nautobot28 мая 2026 г.
- CVE-2026-4479828Наблюдать
Nautobot: GitRepository.current_head field should not be writable through REST API
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %networktocode · nautobot28 мая 2026 г.
- CVE-2026-4479626Наблюдать
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
СредняяCVSS 6,5Эксплойта нетEPSS 1 %networktocode · nautobot28 мая 2026 г.
- CVE-2023-4612826Наблюдать
Exposure of hashed user passwords via REST API in Nautobot
СредняяCVSS 6,5Эксплойта нетEPSS 1 %networktocode · nautobot25 окт. 2023 г.
- CVE-2024-3611226Наблюдать
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
СредняяCVSS 6,5Эксплойта нетEPSS 0 %networktocode · nautobot28 мая 2024 г.
- CVE-2025-4914325Наблюдать
Nautobot may allows uploaded media files to be accessible without authentication
СредняяCVSS 6,3Эксплойта нетEPSS 0 %networktocode · nautobot10 июн. 2025 г.
- CVE-2024-3297924Наблюдать
Reflected Cross-site Scripting potential in all object list views in Nautobot
СредняяCVSS 6,1Эксплойта нетEPSS 0 %networktocode · nautobot1 мая 2024 г.
- CVE-2025-4914224Наблюдать
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
СредняяCVSS 6,0Эксплойта нетEPSS 0 %networktocode · nautobot10 июн. 2025 г.
- CVE-2023-5026321Наблюдать
Nautobot allows unauthenticated db-file-storage views
СредняяCVSS 5,3Эксплойта нетEPSS 1 %networktocode · nautobot12 дек. 2023 г.
- CVE-2024-2919921Наблюдать
Unauthenticated views may expose information to anonymous users
СредняяCVSS 5,3Эксплойта нетEPSS 1 %networktocode · nautobot25 мар. 2024 г.
- CVE-2023-4870521Наблюдать
nautobot has XSS potential in custom links, job buttons, and computed fields
СредняяCVSS 5,4Эксплойта нетEPSS 1 %networktocode · nautobot22 нояб. 2023 г.
- CVE-2024-2334521Наблюдать
Nautobot has XSS potential in rendered Markdown fields
СредняяCVSS 5,4Эксплойта нетEPSS 0 %networktocode · nautobot22 янв. 2024 г.
- CVE-2026-4479421Наблюдать
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
СредняяCVSS 5,4Эксплойта нетEPSS 0 %networktocode · nautobot28 мая 2026 г.
- CVE-2024-3470719Наблюдать
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
СредняяCVSS 4,8Эксплойта нетEPSS 1 %networktocode · nautobot14 мая 2024 г.
- CVE-2023-5164917Наблюдать
Nautobot missing object-level permissions enforcement when running Job Buttons
СредняяCVSS 4,3Эксплойта нетEPSS 0 %networktocode · nautobot22 дек. 2023 г.
- CVE-2026-3420317Наблюдать
Nautobot: Management of users via REST API does not apply configured password validators
СредняяCVSS 4,3Эксплойта нетEPSS 0 %networktocode · nautobot31 мар. 2026 г.