networktocode kayıtları
networktocode üreticisine ait 17 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-400 Uncontrolled Resource Consumption1
- CWE-471 Modification of Assumed-Immutable Data (MAID)1
- CWE-521 Weak Password Requirements1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
17 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-25657İstismar yok | Remote code execution in Jinja2 template rendering in Nautobotnetworktocode · nautobot · CWE-94 | Kritik9,8 | — | %1,5 | 21 Şub 2023 |
34İzleyin | CVE-2026-44797İstismar yok | Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)networktocode · nautobot · CWE-918 | Yüksek8,5 | — | %0,4 | 28 May 2026 |
28İzleyin | CVE-2026-44798İstismar yok | Nautobot: GitRepository.current_head field should not be writable through REST APInetworktocode · nautobot · CWE-471 | Yüksek7,1 | — | %0,5 | 28 May 2026 |
26İzleyin | CVE-2026-44796İstismar yok | Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)networktocode · nautobot · CWE-400 | Orta6,5 | — | %0,6 | 28 May 2026 |
26İzleyin | CVE-2023-46128İstismar yok | Exposure of hashed user passwords via REST API in Nautobotnetworktocode · nautobot · CWE-200 | Orta6,5 | — | %0,5 | 25 Eki 2023 |
26İzleyin | CVE-2024-36112İstismar yok | Nautobot dynamic-group-members doesn't enforce permission restrictions on member objectsnetworktocode · nautobot · CWE-280 | Orta6,5 | — | %0,4 | 28 May 2024 |
25İzleyin | CVE-2025-49143İstismar yok | Nautobot may allows uploaded media files to be accessible without authenticationnetworktocode · nautobot · CWE-200 | Orta6,3 | — | %0,4 | 10 Haz 2025 |
24İzleyin | CVE-2024-32979İstismar yok | Reflected Cross-site Scripting potential in all object list views in Nautobotnetworktocode · nautobot · CWE-79 | Orta6,1 | — | %0,5 | 1 May 2024 |
24İzleyin | CVE-2025-49142İstismar yok | Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templatingnetworktocode · nautobot · CWE-1336 | Orta6,0 | — | %0,4 | 10 Haz 2025 |
21İzleyin | CVE-2023-50263İstismar yok | Nautobot allows unauthenticated db-file-storage viewsnetworktocode · nautobot · CWE-200 | Orta5,3 | — | %0,8 | 12 Ara 2023 |
21İzleyin | CVE-2024-29199İstismar yok | Unauthenticated views may expose information to anonymous usersnetworktocode · nautobot · CWE-200 | Orta5,3 | — | %0,6 | 25 Mar 2024 |
21İzleyin | CVE-2023-48705İstismar yok | nautobot has XSS potential in custom links, job buttons, and computed fieldsnetworktocode · nautobot · CWE-79 | Orta5,4 | — | %0,5 | 22 Kas 2023 |
21İzleyin | CVE-2024-23345İstismar yok | Nautobot has XSS potential in rendered Markdown fieldsnetworktocode · nautobot · CWE-79 | Orta5,4 | — | %0,4 | 22 Oca 2024 |
21İzleyin | CVE-2026-44794İstismar yok | Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to referencenetworktocode · nautobot · CWE-862 | Orta5,4 | — | %0,3 | 28 May 2026 |
19İzleyin | CVE-2024-34707İstismar yok | Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pagesnetworktocode · nautobot · CWE-79 | Orta4,8 | — | %0,6 | 14 May 2024 |
17İzleyin | CVE-2023-51649İstismar yok | Nautobot missing object-level permissions enforcement when running Job Buttonsnetworktocode · nautobot · CWE-863 | Orta4,3 | — | %0,5 | 22 Ara 2023 |
17İzleyin | CVE-2026-34203İstismar yok | Nautobot: Management of users via REST API does not apply configured password validatorsnetworktocode · nautobot · CWE-521 | Orta4,3 | — | %0,3 | 31 Mar 2026 |
- CVE-2023-2565739İzleyin
Remote code execution in Jinja2 template rendering in Nautobot
KritikCVSS 9,8İstismar yokEPSS %2networktocode · nautobot21 Şub 2023
- CVE-2026-4479734İzleyin
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
YüksekCVSS 8,5İstismar yokEPSS %0networktocode · nautobot28 May 2026
- CVE-2026-4479828İzleyin
Nautobot: GitRepository.current_head field should not be writable through REST API
YüksekCVSS 7,1İstismar yokEPSS %0networktocode · nautobot28 May 2026
- CVE-2026-4479626İzleyin
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
OrtaCVSS 6,5İstismar yokEPSS %1networktocode · nautobot28 May 2026
- CVE-2023-4612826İzleyin
Exposure of hashed user passwords via REST API in Nautobot
OrtaCVSS 6,5İstismar yokEPSS %1networktocode · nautobot25 Eki 2023
- CVE-2024-3611226İzleyin
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
OrtaCVSS 6,5İstismar yokEPSS %0networktocode · nautobot28 May 2024
- CVE-2025-4914325İzleyin
Nautobot may allows uploaded media files to be accessible without authentication
OrtaCVSS 6,3İstismar yokEPSS %0networktocode · nautobot10 Haz 2025
- CVE-2024-3297924İzleyin
Reflected Cross-site Scripting potential in all object list views in Nautobot
OrtaCVSS 6,1İstismar yokEPSS %0networktocode · nautobot1 May 2024
- CVE-2025-4914224İzleyin
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
OrtaCVSS 6,0İstismar yokEPSS %0networktocode · nautobot10 Haz 2025
- CVE-2023-5026321İzleyin
Nautobot allows unauthenticated db-file-storage views
OrtaCVSS 5,3İstismar yokEPSS %1networktocode · nautobot12 Ara 2023
- CVE-2024-2919921İzleyin
Unauthenticated views may expose information to anonymous users
OrtaCVSS 5,3İstismar yokEPSS %1networktocode · nautobot25 Mar 2024
- CVE-2023-4870521İzleyin
nautobot has XSS potential in custom links, job buttons, and computed fields
OrtaCVSS 5,4İstismar yokEPSS %1networktocode · nautobot22 Kas 2023
- CVE-2024-2334521İzleyin
Nautobot has XSS potential in rendered Markdown fields
OrtaCVSS 5,4İstismar yokEPSS %0networktocode · nautobot22 Oca 2024
- CVE-2026-4479421İzleyin
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
OrtaCVSS 5,4İstismar yokEPSS %0networktocode · nautobot28 May 2026
- CVE-2024-3470719İzleyin
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
OrtaCVSS 4,8İstismar yokEPSS %1networktocode · nautobot14 May 2024
- CVE-2023-5164917İzleyin
Nautobot missing object-level permissions enforcement when running Job Buttons
OrtaCVSS 4,3İstismar yokEPSS %0networktocode · nautobot22 Ara 2023
- CVE-2026-3420317İzleyin
Nautobot: Management of users via REST API does not apply configured password validators
OrtaCVSS 4,3İstismar yokEPSS %0networktocode · nautobot31 Mar 2026