Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
nautobot Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs Medium Risk 6.4 8 days ago 1 hour ago
nautobot Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages High Risk 7.5 2 years ago 21 days ago
nautobot nautobot has reflected Cross-site Scripting potential in all object list views High Risk 7.5 2 years ago 21 days ago
nautobot Unauthenticated views may expose information to anonymous users Low Risk 3.7 2 years ago 21 days ago
nautobot XSS potential in rendered Markdown fields (comments, description, notes, etc.) High Risk 7.1 2 years ago 21 days ago
nautobot Unauthenticated db-file-storage views Low Risk 3.7 2 years ago 21 days ago
nautobot-device-onboarding Clear Text Credentials Exposed via Onboarding Task Medium Risk 5.7 2 years ago 21 days ago
nautobot Nautobot vulnerable to exposure of hashed user passwords via REST API High Risk 7.7 2 years ago 21 days ago
nautobot Nautobot: Management of users via REST API does not apply configured password validators Low Risk 2.7 6 months ago 2 months ago
nautobot Nautobot: GitRepository.current_head field should not be writable through REST API High Risk 7.1 4 months ago 2 months ago
nautobot Nautobot: Webhook definitions could be used for server-side request forgery (SSRF) High Risk 8.5 4 months ago 2 months ago
nautobot Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference Medium Risk 5.4 4 months ago 2 months ago
nautobot Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS) Medium Risk 6.5 4 months ago 2 months ago
nautobot No summary available Medium Risk 4.3 6 months ago 2 months ago
nautobot No summary available Medium Risk 5.4 4 months ago 2 months ago
nautobot No summary available Medium Risk 6.5 4 months ago 2 months ago
nautobot No summary available High Risk 8.5 4 months ago 2 months ago
nautobot No summary available High Risk 7.1 4 months ago 2 months ago
nautobot-ssot Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL Medium Risk 5.3 11 months ago 2 months ago
nautobot Nautobot may allows uploaded media files to be accessible without authentication Medium Risk 6.0 1 year ago 2 months ago
nautobot Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages High Risk 7.5 2 months ago 2 months ago
nautobot Nautobot may allows uploaded media files to be accessible without authentication Unknown 2 months ago 2 months ago
nautobot nautobot has reflected Cross-site Scripting potential in all object list views High Risk 7.5 2 months ago 2 months ago
nautobot Unauthenticated views may expose information to anonymous users Low Risk 3.7 2 months ago 2 months ago
nautobot-ssot Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL Medium Risk 5.3 2 months ago 2 months ago
nautobot No summary available Unknown 2 years ago 3 months ago
nautobot Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects Medium Risk 6.3 2 years ago 3 months ago
nautobot Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating Medium Risk 6.0 1 year ago 3 months ago
nautobot No summary available High Risk 7.1 1 year ago 3 months ago
nautobot Nautobot missing object-level permissions enforcement when running Job Buttons Low Risk 3.5 2 years ago 3 months ago
nautobot No summary available Medium Risk 5.3 2 years ago 3 months ago
nautobot No summary available Medium Risk 4.3 2 years ago 3 months ago
nautobot Cross-site Scripting potential in custom links, job buttons, and computed fields High Risk 7.1 2 years ago 1 year ago
nautobot No summary available Medium Risk 5.4 2 years ago 1 year ago
nautobot-device-onboarding No summary available Medium Risk 6.5 2 years ago 1 year ago
nautobot Nautobot vulnerable to remote code execution via Jinja2 template rendering High Risk 7.5 3 years ago 2 years ago
nautobot No summary available Medium Risk 5.4 2 years ago 2 years ago
nautobot No summary available Medium Risk 6.5 2 years ago 2 years ago
nautobot No summary available Unknown 3 years ago 2 years ago