zeit records
9 published records for vendor zeit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-177 Improper Handling of URL Encoding (Hex Encoding)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-23 Relative Path Traversal1
- CWE-548 Exposure of Information Through Directory Listing1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2017-16877Proof of concept | ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive infzeit · next.js · CWE-22 | High7.5 | — | 14.1% | Nov 17, 2017 |
33Monitor | CVE-2018-6184Proof of concept | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.zeit · next.js · CWE-22 | High7.5 | — | 9.1% | Jan 24, 2018 |
31Monitor | CVE-2019-5417No exploit | A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote servzeit · serve · CWE-22 | High7.5 | — | 2.3% | Mar 21, 2019 |
30Monitor | CVE-2020-5284Proof of concept | Directory Traversal in Next.js versions below 9.3.2zeit · next.js · CWE-23 | Medium4.3 | — | 44.3% | Mar 30, 2020 |
30Monitor | CVE-2019-5415No exploit | A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the vzeit · serve · CWE-548 | High7.5 | — | 1.6% | Mar 21, 2019 |
27Monitor | CVE-2018-3712No exploit | serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in pathzeit · serve · CWE-22 | Medium6.5 | — | 1.8% | Jun 6, 2018 |
24Monitor | CVE-2018-18282No exploit | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.zeit · next.js · CWE-79 | Medium6.1 | — | 1.0% | Oct 12, 2018 |
21Monitor | CVE-2018-3718No exploit | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.zeit · serve · CWE-177 | Medium5.3 | — | 1.3% | Jun 6, 2018 |
21Monitor | CVE-2018-3809No exploit | Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be izeit · serve · CWE-200 | Medium5.3 | — | 1.0% | Jun 1, 2018 |
- CVE-2017-1687734Monitor
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive inf
HighCVSS 7.5Proof of conceptEPSS 14%zeit · next.jsNov 17, 2017
- CVE-2018-618433Monitor
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
HighCVSS 7.5Proof of conceptEPSS 9%zeit · next.jsJan 24, 2018
- CVE-2019-541731Monitor
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote serv
HighCVSS 7.5No exploitEPSS 2%zeit · serveMar 21, 2019
- CVE-2020-528430Monitor
Directory Traversal in Next.js versions below 9.3.2
MediumCVSS 4.3Proof of conceptEPSS 44%zeit · next.jsMar 30, 2020
- CVE-2019-541530Monitor
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the v
HighCVSS 7.5No exploitEPSS 2%zeit · serveMar 21, 2019
- CVE-2018-371227Monitor
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in path
MediumCVSS 6.5No exploitEPSS 2%zeit · serveJun 6, 2018
- CVE-2018-1828224Monitor
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
MediumCVSS 6.1No exploitEPSS 1%zeit · next.jsOct 12, 2018
- CVE-2018-371821Monitor
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
MediumCVSS 5.3No exploitEPSS 1%zeit · serveJun 6, 2018
- CVE-2018-380921Monitor
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be i
MediumCVSS 5.3No exploitEPSS 1%zeit · serveJun 1, 2018