Launch Week Day 1: Announcing Security Design Review
25 Total advisories
25 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
PyPI

CVE-2024-36112

CVE-2024-36112

MEDIUM 6.3
PyPI

CVE-2024-36112

Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects

HIGH 7.1
PyPI

CVE-2025-49142

CVE-2025-49142

UNKNOWN
PyPI

CVE-2025-49142

Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating

LOW 3.5
PyPI

CVE-2023-51649

Nautobot missing object-level permissions enforcement when running Job Buttons

HIGH 8.5
PyPI

CVE-2026-44797

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

HIGH 7.1
PyPI

CVE-2026-44798

Nautobot: GitRepository.current_head field should not be writable through REST API

MEDIUM 6.5
PyPI

CVE-2026-44796

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

MEDIUM 5.4
PyPI

CVE-2026-44794

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

MEDIUM 5.3
PyPI

CVE-2023-50263

CVE-2023-50263

MEDIUM 4.3
PyPI

CVE-2023-51649

CVE-2023-51649

LOW 2.7
PyPI

CVE-2026-34203

Nautobot: Management of users via REST API does not apply configured password validators

UNKNOWN
PyPI

CVE-2025-49143

Nautobot may allows uploaded media files to be accessible without authentication

HIGH 7.1
PyPI

CVE-2024-23345

XSS potential in rendered Markdown fields (comments, description, notes, etc.)

HIGH 7.1
PyPI

CVE-2023-48705

Cross-site Scripting potential in custom links, job buttons, and computed fields

LOW 3.7
PyPI

CVE-2023-50263

Unauthenticated db-file-storage views

MEDIUM 5.4
PyPI

CVE-2023-48705

CVE-2023-48705

HIGH 7.7
PyPI

CVE-2023-46128

Nautobot vulnerable to exposure of hashed user passwords via REST API

HIGH 7.5
PyPI

CVE-2023-25657

Nautobot vulnerable to remote code execution via Jinja2 template rendering

HIGH 7.5
PyPI

CVE-2024-34707

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

HIGH 7.5
PyPI

CVE-2024-32979

nautobot has reflected Cross-site Scripting potential in all object list views

LOW 3.7
PyPI

CVE-2024-29199

Unauthenticated views may expose information to anonymous users

MEDIUM 5.4
PyPI

CVE-2024-23345

CVE-2024-23345

MEDIUM 6.5
PyPI

CVE-2023-46128

CVE-2023-46128

UNKNOWN
PyPI

CVE-2023-25657

CVE-2023-25657

Ready to move

Start Securing

Free, no credit card | First findings in minutes