VulnSea

netbox-community has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-829 (3). Most affected products: devicetype-library (3), netbox (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
5 prev 0

Products

  • devicetype-library 3
  • netbox 2
5
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

netbox-community vulnerabilities

CVEs affecting netbox-community, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-54916High· 8.8
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests dire…

Twilightnetbox-community · devicetype-libraryEPSS 0.41%via NVD
CVE-2026-54918Medium· 5.3
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…

Sunlitnetbox-community · devicetype-libraryEPSS 0.30%via NVD
CVE-2026-54752Critical· 9.6
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…

Midnightnetbox-community · devicetype-libraryEPSS 0.35%via NVD
CVE-2026-86176Medium· 4.3
2w ago

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through …

Sunlitnetbox-community · netboxEPSS 0.20%via NVD
CVE-2026-86175Medium· 6.5PoC
2w ago

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backen…

Twilightnetbox-community · netboxEPSS 0.26%via NVD
netbox-community vulnerabilities (CVEs) · VulnSea