Skip to content
Noroxi

zeit records

9 published records for vendor zeit.

All records

9 records
  • ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive inf

    HighCVSS 7.5Proof of conceptEPSS 14%

    zeit · next.jsNov 17, 2017

  • CVE-2018-6184
    33Monitor

    ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

    HighCVSS 7.5Proof of conceptEPSS 9%

    zeit · next.jsJan 24, 2018

  • CVE-2019-5417
    31Monitor

    A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote serv

    HighCVSS 7.5No exploitEPSS 2%

    zeit · serveMar 21, 2019

  • CVE-2020-5284
    30Monitor

    Directory Traversal in Next.js versions below 9.3.2

    MediumCVSS 4.3Proof of conceptEPSS 44%

    zeit · next.jsMar 30, 2020

  • CVE-2019-5415
    30Monitor

    A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the v

    HighCVSS 7.5No exploitEPSS 2%

    zeit · serveMar 21, 2019

  • CVE-2018-3712
    27Monitor

    serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in path

    MediumCVSS 6.5No exploitEPSS 2%

    zeit · serveJun 6, 2018

  • Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.

    MediumCVSS 6.1No exploitEPSS 1%

    zeit · next.jsOct 12, 2018

  • CVE-2018-3718
    21Monitor

    serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

    MediumCVSS 5.3No exploitEPSS 1%

    zeit · serveJun 6, 2018

  • CVE-2018-3809
    21Monitor

    Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be i

    MediumCVSS 5.3No exploitEPSS 1%

    zeit · serveJun 1, 2018