İçeriğe atla
Noroxi

networktocode kayıtları

networktocode üreticisine ait 17 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

17 kayıt
  • CVE-2023-25657
    39İzleyin

    Remote code execution in Jinja2 template rendering in Nautobot

    KritikCVSS 9,8İstismar yokEPSS %2

    networktocode · nautobot21 Şub 2023

  • CVE-2026-44797
    34İzleyin

    Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

    YüksekCVSS 8,5İstismar yokEPSS %0

    networktocode · nautobot28 May 2026

  • CVE-2026-44798
    28İzleyin

    Nautobot: GitRepository.current_head field should not be writable through REST API

    YüksekCVSS 7,1İstismar yokEPSS %0

    networktocode · nautobot28 May 2026

  • CVE-2026-44796
    26İzleyin

    Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

    OrtaCVSS 6,5İstismar yokEPSS %1

    networktocode · nautobot28 May 2026

  • CVE-2023-46128
    26İzleyin

    Exposure of hashed user passwords via REST API in Nautobot

    OrtaCVSS 6,5İstismar yokEPSS %1

    networktocode · nautobot25 Eki 2023

  • CVE-2024-36112
    26İzleyin

    Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects

    OrtaCVSS 6,5İstismar yokEPSS %0

    networktocode · nautobot28 May 2024

  • CVE-2025-49143
    25İzleyin

    Nautobot may allows uploaded media files to be accessible without authentication

    OrtaCVSS 6,3İstismar yokEPSS %0

    networktocode · nautobot10 Haz 2025

  • CVE-2024-32979
    24İzleyin

    Reflected Cross-site Scripting potential in all object list views in Nautobot

    OrtaCVSS 6,1İstismar yokEPSS %0

    networktocode · nautobot1 May 2024

  • CVE-2025-49142
    24İzleyin

    Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating

    OrtaCVSS 6,0İstismar yokEPSS %0

    networktocode · nautobot10 Haz 2025

  • CVE-2023-50263
    21İzleyin

    Nautobot allows unauthenticated db-file-storage views

    OrtaCVSS 5,3İstismar yokEPSS %1

    networktocode · nautobot12 Ara 2023

  • CVE-2024-29199
    21İzleyin

    Unauthenticated views may expose information to anonymous users

    OrtaCVSS 5,3İstismar yokEPSS %1

    networktocode · nautobot25 Mar 2024

  • CVE-2023-48705
    21İzleyin

    nautobot has XSS potential in custom links, job buttons, and computed fields

    OrtaCVSS 5,4İstismar yokEPSS %1

    networktocode · nautobot22 Kas 2023

  • CVE-2024-23345
    21İzleyin

    Nautobot has XSS potential in rendered Markdown fields

    OrtaCVSS 5,4İstismar yokEPSS %0

    networktocode · nautobot22 Oca 2024

  • CVE-2026-44794
    21İzleyin

    Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

    OrtaCVSS 5,4İstismar yokEPSS %0

    networktocode · nautobot28 May 2026

  • CVE-2024-34707
    19İzleyin

    Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

    OrtaCVSS 4,8İstismar yokEPSS %1

    networktocode · nautobot14 May 2024

  • CVE-2023-51649
    17İzleyin

    Nautobot missing object-level permissions enforcement when running Job Buttons

    OrtaCVSS 4,3İstismar yokEPSS %0

    networktocode · nautobot22 Ara 2023

  • CVE-2026-34203
    17İzleyin

    Nautobot: Management of users via REST API does not apply configured password validators

    OrtaCVSS 4,3İstismar yokEPSS %0

    networktocode · nautobot31 Mar 2026