nextauth.js records
9 published records for vendor nextauth.js.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-290 Authentication Bypass by Spoofing2
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-754 Improper Check for Unusual or Exceptional Conditions1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-35924No exploit | Verification requests (magic link) sent to unwanted emailsnextauth.js · next-auth · CWE-20 | Critical9.1 | — | 1.4% | Aug 2, 2022 |
35Monitor | CVE-2023-27490No exploit | Missing proper state, nonce and PKCE checks for OAuth authentication in next-authnextauth.js · next-auth · CWE-352 | High8.8 | — | 0.5% | Mar 9, 2023 |
32Monitor | CVE-2022-39263No exploit | NextAuth.js Upstash Adapter missing token verificationnextauth.js · next-auth · CWE-287 | High8.1 | — | 0.7% | Sep 28, 2022 |
31Monitor | CVE-2022-31093No exploit | Improper Handling of `callbackUrl` parameter in next-authnextauth.js · next-auth · CWE-754 | High7.5 | — | 1.7% | Jun 27, 2022 |
24Monitor | CVE-2021-21310No exploit | Token verification bug in next-authnextauth.js · next-auth · CWE-290 | Medium5.9 | — | 1.7% | Feb 11, 2021 |
24Monitor | CVE-2022-31127No exploit | Improper handling of email input in next-authnextauth.js · next-auth · CWE-79 | Medium6.1 | — | 1.1% | Jul 6, 2022 |
24Monitor | CVE-2022-24858No exploit | Default redirect callback vulnerable to open redirectsnextauth.js · next-auth · CWE-290 | Medium6.1 | — | 0.8% | Apr 19, 2022 |
24Monitor | CVE-2022-29214No exploit | URL Redirection to Untrusted Site ('Open Redirect') in next-authnextauth.js · next-auth · CWE-601 | Medium6.1 | — | 0.7% | May 20, 2022 |
21Monitor | CVE-2023-48309No exploit | next-auth vulnerable to possible user mocking that bypasses basic authenticationnextauth.js · next-auth · CWE-285 | Medium5.3 | — | 0.7% | Nov 20, 2023 |
- CVE-2022-3592436Monitor
Verification requests (magic link) sent to unwanted emails
CriticalCVSS 9.1No exploitEPSS 1%nextauth.js · next-authAug 2, 2022
- CVE-2023-2749035Monitor
Missing proper state, nonce and PKCE checks for OAuth authentication in next-auth
HighCVSS 8.8No exploitEPSS 1%nextauth.js · next-authMar 9, 2023
- CVE-2022-3926332Monitor
NextAuth.js Upstash Adapter missing token verification
HighCVSS 8.1No exploitEPSS 1%nextauth.js · next-authSep 28, 2022
- CVE-2022-3109331Monitor
Improper Handling of `callbackUrl` parameter in next-auth
HighCVSS 7.5No exploitEPSS 2%nextauth.js · next-authJun 27, 2022
- CVE-2021-2131024Monitor
Token verification bug in next-auth
MediumCVSS 5.9No exploitEPSS 2%nextauth.js · next-authFeb 11, 2021
- CVE-2022-3112724Monitor
Improper handling of email input in next-auth
MediumCVSS 6.1No exploitEPSS 1%nextauth.js · next-authJul 6, 2022
- CVE-2022-2485824Monitor
Default redirect callback vulnerable to open redirects
MediumCVSS 6.1No exploitEPSS 1%nextauth.js · next-authApr 19, 2022
- CVE-2022-2921424Monitor
URL Redirection to Untrusted Site ('Open Redirect') in next-auth
MediumCVSS 6.1No exploitEPSS 1%nextauth.js · next-authMay 20, 2022
- CVE-2023-4830921Monitor
next-auth vulnerable to possible user mocking that bypasses basic authentication
MediumCVSS 5.3No exploitEPSS 1%nextauth.js · next-authNov 20, 2023