CVE-2025-49143
- EPSS 0.07%
- Veröffentlicht 10.06.2025 15:43:59
- Zuletzt bearbeitet 21.08.2025 22:34:19
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device,...
CVE-2025-49142
- EPSS 0.06%
- Veröffentlicht 10.06.2025 15:40:21
- Zuletzt bearbeitet 21.08.2025 22:36:18
Nautobot is a Network Source of Truth and Network Automation Platform. All users of Nautobot versions prior to 2.4.10 or prior to 1.6.32 are potentially affected. Due to insufficient security configuration of the Jinja2 templating feature used in com...
CVE-2024-36112
- EPSS 0.15%
- Veröffentlicht 28.05.2024 23:15:17
- Zuletzt bearbeitet 26.08.2025 16:21:03
Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group records (`extras.view_dynamicgroup` permission) can use the Dynamic Group detail UI view (`/extras/dynamic-groups/<uuid>/`) and/or th...
CVE-2024-34707
- EPSS 0.27%
- Veröffentlicht 14.05.2024 15:39:30
- Zuletzt bearbeitet 26.08.2025 16:16:00
Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally...
CVE-2024-32979
- EPSS 0.2%
- Veröffentlicht 01.05.2024 11:15:47
- Zuletzt bearbeitet 26.08.2025 18:54:06
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query...
CVE-2024-29199
- EPSS 0.13%
- Veröffentlicht 26.03.2024 03:15:13
- Zuletzt bearbeitet 26.08.2025 17:18:09
Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to be improperly accessible to unauthenticated (anonymous) users. These endpoints will not disclose any Nautobot data to an unauthent...
CVE-2024-23345
- EPSS 0.41%
- Veröffentlicht 23.01.2024 00:15:26
- Zuletzt bearbeitet 21.11.2024 08:57:33
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot versions earlier than 1.6.10 or 2.1.2 are potentially impacted by a cross-site scripting vulnerability. Due to inadequate input s...
CVE-2023-51649
- EPSS 0.1%
- Veröffentlicht 22.12.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:38:32
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. When submitting a Job to run via a Job Button, only the model-level `extras.run_job...
CVE-2023-50263
- EPSS 0.45%
- Veröffentlicht 12.12.2023 23:15:07
- Zuletzt bearbeitet 21.11.2024 08:36:46
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 1.x and 2.0.x prior to 1.6.7 and 2.0.6, the URLs `/files/get/?name=...`...
CVE-2023-48705
- EPSS 0.3%
- Veröffentlicht 22.11.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:32:17
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot versions earlier than 1.6.6 or 2.0.5 are potentially affected by a cross-site scripting vulnerability. Due to incorrect usage of Dj...