VulnSea

nautobot has 12 CVEs on record between 2023 and 2026. The busiest recent month was May 2026 with 4. The median CVSS is 7.1 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
0 prev 5

Products

  • nautobot 12
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

nautobot vulnerabilities

CVEs affecting nautobot, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-44794Medium· 5.4
4mo ago

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference

Sunlitnautobot · nautobotEPSS 0.18%via OSV
CVE-2026-44796Medium· 6.5
4mo ago

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)

Sunlitnautobot · nautobotEPSS 0.31%via OSV
CVE-2026-44798High· 7.1
4mo ago

Nautobot: GitRepository.current_head field should not be writable through REST API

Nautobot: GitRepository.current_head field should not be writable through REST API

Twilightnautobot · nautobotEPSS 0.28%via OSV
CVE-2026-44797High· 8.5
4mo ago

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

Twilightnautobot · nautobotEPSS 0.24%via OSV
CVE-2026-34203Low· 2.7
5mo ago

Nautobot: Management of users via REST API does not apply configured password validators

Nautobot: Management of users via REST API does not apply configured password validators

Sunlitnautobot · nautobotEPSS 0.24%via OSV
CVE-2025-49143Medium
1y ago

Nautobot may allows uploaded media files to be accessible without authentication

Nautobot may allows uploaded media files to be accessible without authentication

Sunlitnautobot · nautobotEPSS 0.44%via OSV
CVE-2024-34707High· 7.5
2y ago

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages

Twilightnautobot · nautobotEPSS 0.61%via OSV
CVE-2024-32979High· 7.5
2y ago

nautobot has reflected Cross-site Scripting potential in all object list views

nautobot has reflected Cross-site Scripting potential in all object list views

Twilightnautobot · nautobotEPSS 0.49%via OSV
CVE-2024-29199Low· 3.7
2y ago

Unauthenticated views may expose information to anonymous users

Unauthenticated views may expose information to anonymous users

Sunlitnautobot · nautobotEPSS 0.63%via OSV
CVE-2024-23345High· 7.1
2y ago

XSS potential in rendered Markdown fields (comments, description, notes, etc.)

XSS potential in rendered Markdown fields (comments, description, notes, etc.)

Twilightnautobot · nautobotEPSS 0.43%via OSV
CVE-2023-50263Low· 3.7
2y ago

Unauthenticated db-file-storage views

Unauthenticated db-file-storage views

Sunlitnautobot · nautobotEPSS 0.75%via OSV
CVE-2023-46128High· 7.7
2y ago

Nautobot vulnerable to exposure of hashed user passwords via REST API

Nautobot vulnerable to exposure of hashed user passwords via REST API

Twilightnautobot · nautobotEPSS 0.53%via OSV
nautobot vulnerabilities (CVEs) · VulnSea