vercel records
69 published records for vendor vercel.
Researcher profile
- Entered KEV
- 1 · 1.4%
- Weaponized
- 2 · 2.9%
- Pre-auth RCE
- 4
- With a fix record
- 92.8%
- Median publish → KEV
- 2 days
Recurring classes
- CWE-400 Uncontrolled Resource Consumption6
- CWE-770 Allocation of Resources Without Limits or Throttling5
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-502 Deserialization of Untrusted Data4
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')4
- CWE-288 Authentication Bypass Using an Alternate Path or Channel3
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
69 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-55182Weaponized | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Critical10.0 | KEV | 99.8% | Dec 3, 2025 |
66This week | CVE-2025-29927Weaponized | Authorization Bypass in Next.js Middlewarevercel · next.js · CWE-285 | Critical9.1 | — | 99.2% | Mar 21, 2025 |
50Plan | CVE-2025-55184Proof of concept | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.facebook · react · CWE-502 | High7.5 | — | 66.9% | Dec 11, 2025 |
48Plan | CVE-2024-46982Proof of concept | Cache Poisoning in next.jsvercel · next.js · CWE-639 | High7.5 | — | 59.2% | Sep 17, 2024 |
43Plan | CVE-2021-43803No exploit | Unexpected server crash in Next.jsvercel · next.js · CWE-20 | High7.5 | — | 44.8% | Dec 9, 2021 |
40Plan | CVE-2025-55183Proof of concept | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.vercel · next.js · CWE-502 | Medium5.3 | — | 64.2% | Dec 11, 2025 |
39Monitor | CVE-2024-23741Proof of concept | An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnvercel · hyper · CWE-94 | Critical9.8 | — | 1.6% | Jan 27, 2024 |
36Monitor | CVE-2025-67779No exploit | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attacfacebook · react · CWE-502 | High7.5 | — | 20.0% | Dec 11, 2025 |
35Monitor | CVE-2026-44578Proof of concept | Next.js: Server-side request forgery in applications using WebSocket upgradesvercel · next.js · CWE-918 | High8.6 | — | 1.9% | May 13, 2026 |
33Monitor | CVE-2025-57822Proof of concept | Next.js Improper Middleware Redirect Handling Leads to SSRFvercel · next.js · CWE-918 | High8.2 | — | 2.5% | Aug 29, 2025 |
33Monitor | CVE-2026-64642No exploit | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localevercel · next.js · CWE-285 | High8.3 | — | 0.6% | Jul 27, 2026 |
33Monitor | CVE-2026-64649No exploit | Next.js: Server-Side Request Forgery in Server Actions on Custom Serversvercel · next.js · CWE-918 | High8.3 | — | 0.5% | Jul 27, 2026 |
33Monitor | CVE-2026-64645No exploit | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamevercel · next.js · CWE-601 | High8.3 | — | 0.4% | Jul 27, 2026 |
33Monitor | CVE-2026-46508No exploit | Turborepo: VSCode Extension command injectionvercel · turborepo language server protocol · CWE-77 | High8.4 | — | 0.2% | May 15, 2026 |
32Monitor | CVE-2015-8315No exploit | The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "revercel · ms · CWE-1333 | High7.5 | — | 6.8% | Jan 23, 2017 |
32Monitor | CVE-2024-34351Proof of concept | Next.js Server-Side Request Forgery in Server Actionsvercel · next.js · CWE-918 | High7.5 | — | 5.5% | May 14, 2024 |
32Monitor | CVE-2026-64641No exploit | Next.js: Denial of Service in App Router using Server Actionsvercel · next.js · CWE-834 | High8.2 | — | 0.9% | Jul 27, 2026 |
32Monitor | CVE-2026-44574No exploit | Next.js: Middleware / Proxy bypass through dynamic route parameter injectionvercel · next.js · CWE-288 | High8.1 | — | 0.7% | May 13, 2026 |
31Monitor | CVE-2024-51479No exploit | Authorization bypass in Next.jsvercel · next.js · CWE-285 | High7.5 | — | 4.0% | Dec 17, 2024 |
31Monitor | CVE-2022-21721No exploit | DOS Vulnerability in next.jsvercel · next.js | High7.5 | — | 2.2% | Jan 28, 2022 |
31Monitor | CVE-2022-23646No exploit | Improper CSP in Image Optimization API for Next.jsvercel · next.js · CWE-451 | High7.5 | — | 1.8% | Feb 17, 2022 |
31Monitor | CVE-2024-24828No exploit | Local Privilege Escalation in execuatables bundled by pkgvercel · pkg · CWE-276 | High7.8 | — | 0.2% | Feb 9, 2024 |
30Monitor | CVE-2023-46298No exploit | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a vercel · next.js | High7.5 | — | 1.3% | Oct 21, 2023 |
30Monitor | CVE-2024-34350No exploit | Next.js Vulnerable to HTTP Request Smugglingvercel · next.js · CWE-444 | High7.5 | — | 1.2% | May 14, 2024 |
30Monitor | CVE-2025-49826No exploit | Next.js DoS vulnerability via cache poisoningvercel · next.js · CWE-444 | High7.5 | — | 1.1% | Jul 3, 2025 |
- CVE-2025-55182100Now
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
CriticalCVSS 10.0KEVWeaponizedEPSS 100%facebook · reactDec 3, 2025
- CVE-2025-2992766This week
Authorization Bypass in Next.js Middleware
CriticalCVSS 9.1WeaponizedEPSS 99%vercel · next.jsMar 21, 2025
- CVE-2025-5518450Plan
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.
HighCVSS 7.5Proof of conceptEPSS 67%facebook · reactDec 11, 2025
- CVE-2024-4698248Plan
Cache Poisoning in next.js
HighCVSS 7.5Proof of conceptEPSS 59%vercel · next.jsSep 17, 2024
- CVE-2021-4380343Plan
Unexpected server crash in Next.js
HighCVSS 7.5No exploitEPSS 45%vercel · next.jsDec 9, 2021
- CVE-2025-5518340Plan
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.
MediumCVSS 5.3Proof of conceptEPSS 64%vercel · next.jsDec 11, 2025
- CVE-2024-2374139Monitor
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeCliln
CriticalCVSS 9.8Proof of conceptEPSS 2%vercel · hyperJan 27, 2024
- CVE-2025-6777936Monitor
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attac
HighCVSS 7.5No exploitEPSS 20%facebook · reactDec 11, 2025
- CVE-2026-4457835Monitor
Next.js: Server-side request forgery in applications using WebSocket upgrades
HighCVSS 8.6Proof of conceptEPSS 2%vercel · next.jsMay 13, 2026
- CVE-2025-5782233Monitor
Next.js Improper Middleware Redirect Handling Leads to SSRF
HighCVSS 8.2Proof of conceptEPSS 2%vercel · next.jsAug 29, 2025
- CVE-2026-6464233Monitor
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
HighCVSS 8.3No exploitEPSS 1%vercel · next.jsJul 27, 2026
- CVE-2026-6464933Monitor
Next.js: Server-Side Request Forgery in Server Actions on Custom Servers
HighCVSS 8.3No exploitEPSS 0%vercel · next.jsJul 27, 2026
- CVE-2026-6464533Monitor
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
HighCVSS 8.3No exploitEPSS 0%vercel · next.jsJul 27, 2026
- CVE-2026-4650833Monitor
Turborepo: VSCode Extension command injection
HighCVSS 8.4No exploitEPSS 0%vercel · turborepo language server protocolMay 15, 2026
- CVE-2015-831532Monitor
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "re
HighCVSS 7.5No exploitEPSS 7%vercel · msJan 23, 2017
- CVE-2024-3435132Monitor
Next.js Server-Side Request Forgery in Server Actions
HighCVSS 7.5Proof of conceptEPSS 5%vercel · next.jsMay 14, 2024
- CVE-2026-6464132Monitor
Next.js: Denial of Service in App Router using Server Actions
HighCVSS 8.2No exploitEPSS 1%vercel · next.jsJul 27, 2026
- CVE-2026-4457432Monitor
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
HighCVSS 8.1No exploitEPSS 1%vercel · next.jsMay 13, 2026
- CVE-2024-5147931Monitor
Authorization bypass in Next.js
HighCVSS 7.5No exploitEPSS 4%vercel · next.jsDec 17, 2024
- CVE-2022-2172131Monitor
DOS Vulnerability in next.js
HighCVSS 7.5No exploitEPSS 2%vercel · next.jsJan 28, 2022
- CVE-2022-2364631Monitor
Improper CSP in Image Optimization API for Next.js
HighCVSS 7.5No exploitEPSS 2%vercel · next.jsFeb 17, 2022
- CVE-2024-2482831Monitor
Local Privilege Escalation in execuatables bundled by pkg
HighCVSS 7.8No exploitEPSS 0%vercel · pkgFeb 9, 2024
- CVE-2023-4629830Monitor
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a
HighCVSS 7.5No exploitEPSS 1%vercel · next.jsOct 21, 2023
- CVE-2024-3435030Monitor
Next.js Vulnerable to HTTP Request Smuggling
HighCVSS 7.5No exploitEPSS 1%vercel · next.jsMay 14, 2024
- CVE-2025-4982630Monitor
Next.js DoS vulnerability via cache poisoning
HighCVSS 7.5No exploitEPSS 1%vercel · next.jsJul 3, 2025