Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2199719
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9292
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2734
Debian
68378
Echo
7422
GHC
3
GIT
108138
GitHub Actions
55
Go
9203
Hackage
32
Hex
364
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144419
npm
228744
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25171
Red Hat
23355
Rocky Linux
4298
Root
19553
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9512
Ubuntu
65374
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-q4c5-2j6f-r476
PyPI/nautobot
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs
5 days ago
Fix available
Severity - 6.4 (Medium)
GHSA-56v6-2fhr-wxgq
PyPI/nautobot
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text
5 days ago
Fix available
Severity - 5.4 (Medium)
PYSEC-2026-1690
PyPI/nautobot-ssot
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1689
PyPI/nautobot
Nautobot may allows uploaded media files to be accessible without authentication
07 Jul
Fix available
Severity - 6.3 (Medium)
PYSEC-2026-1688
PyPI/nautobot
Nautobot's BANNER_* configuration can be used to inject arbitrary HTML content into Nautobot pages
07 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1686
PyPI/nautobot
nautobot has reflected Cross-site Scripting potential in all object list views
07 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1687
PyPI/nautobot
Unauthenticated views may expose information to anonymous users
07 Jul
Fix available
Severity - 3.7 (Low)
PYSEC-2026-2228
PyPI/nautobot
See record for full details
28 May
Fix available
Severity - 7.1 (High)
PYSEC-2026-2227
PyPI/nautobot
See record for full details
28 May
Fix available
Severity - 8.5 (High)
PYSEC-2026-2226
PyPI/nautobot
See record for full details
28 May
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2225
PyPI/nautobot
See record for full details
28 May
Fix available
Severity - 5.4 (Medium)
GHSA-p3hx-pwf3-j8wr
PyPI/nautobot
Nautobot: GitRepository.current_head field should not be writable through REST API
13 May
Fix available
Severity - 7.1 (High)
GHSA-c35q-vxrp-ph26
PyPI/nautobot
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
13 May
Fix available
Severity - 8.5 (High)
GHSA-qrpw-gjvh-x5gm
PyPI/nautobot
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
13 May
Fix available
Severity - 6.5 (Medium)
GHSA-wpxj-44w3-2j6x
PyPI/nautobot
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
13 May
Fix available
Severity - 5.4 (Medium)
GHSA-xmpv-j7p2-j873
PyPI/nautobot
Nautobot: Management of users via REST API does not apply configured password validators
31 Mar
Fix available
Severity - 2.7 (Low)
Load more...
PyPI - OSV