networktocode
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 17 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 21, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Nautobot: GitRepository.current_head field should not be writable through REST API
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Nautobot: Management of users via REST API does not apply configured password validators
Nautobot may allows uploaded media files to be accessible without authentication
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
Reflected Cross-site Scripting potential in all object list views in Nautobot
Monitor networktocode in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.