Записи vercel
69 опубликованных записей вендора vercel.
Профиль для исследователя
- Попали в KEV
- 1 · 1,4 %
- С эксплойтом
- 2 · 2,9 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 92,8 %
- Медиана: публикация → KEV
- 2 дн.
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption6
- CWE-770 Allocation of Resources Without Limits or Throttling5
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-502 Deserialization of Untrusted Data4
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')4
- CWE-288 Authentication Bypass Using an Alternate Path or Channel3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
69 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2025-55182Готовый эксплойт | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Критическая10,0 | KEV | 99,8 % | 3 дек. 2025 г. |
66На этой неделе | CVE-2025-29927Готовый эксплойт | Authorization Bypass in Next.js Middlewarevercel · next.js · CWE-285 | Критическая9,1 | — | 99,2 % | 21 мар. 2025 г. |
50В плане | CVE-2025-55184Proof of concept | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.facebook · react · CWE-502 | Высокая7,5 | — | 66,9 % | 11 дек. 2025 г. |
48В плане | CVE-2024-46982Proof of concept | Cache Poisoning in next.jsvercel · next.js · CWE-639 | Высокая7,5 | — | 59,2 % | 17 сент. 2024 г. |
43В плане | CVE-2021-43803Эксплойта нет | Unexpected server crash in Next.jsvercel · next.js · CWE-20 | Высокая7,5 | — | 44,8 % | 9 дек. 2021 г. |
40В плане | CVE-2025-55183Proof of concept | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.vercel · next.js · CWE-502 | Средняя5,3 | — | 64,2 % | 11 дек. 2025 г. |
39Наблюдать | CVE-2024-23741Proof of concept | An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnvercel · hyper · CWE-94 | Критическая9,8 | — | 1,6 % | 27 янв. 2024 г. |
36Наблюдать | CVE-2025-67779Эксплойта нет | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attacfacebook · react · CWE-502 | Высокая7,5 | — | 20,0 % | 11 дек. 2025 г. |
35Наблюдать | CVE-2026-44578Proof of concept | Next.js: Server-side request forgery in applications using WebSocket upgradesvercel · next.js · CWE-918 | Высокая8,6 | — | 1,9 % | 13 мая 2026 г. |
33Наблюдать | CVE-2025-57822Proof of concept | Next.js Improper Middleware Redirect Handling Leads to SSRFvercel · next.js · CWE-918 | Высокая8,2 | — | 2,5 % | 29 авг. 2025 г. |
33Наблюдать | CVE-2026-64642Эксплойта нет | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localevercel · next.js · CWE-285 | Высокая8,3 | — | 0,6 % | 27 июл. 2026 г. |
33Наблюдать | CVE-2026-64649Эксплойта нет | Next.js: Server-Side Request Forgery in Server Actions on Custom Serversvercel · next.js · CWE-918 | Высокая8,3 | — | 0,5 % | 27 июл. 2026 г. |
33Наблюдать | CVE-2026-64645Эксплойта нет | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamevercel · next.js · CWE-601 | Высокая8,3 | — | 0,4 % | 27 июл. 2026 г. |
33Наблюдать | CVE-2026-46508Эксплойта нет | Turborepo: VSCode Extension command injectionvercel · turborepo language server protocol · CWE-77 | Высокая8,4 | — | 0,2 % | 15 мая 2026 г. |
32Наблюдать | CVE-2015-8315Эксплойта нет | The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "revercel · ms · CWE-1333 | Высокая7,5 | — | 6,8 % | 23 янв. 2017 г. |
32Наблюдать | CVE-2024-34351Proof of concept | Next.js Server-Side Request Forgery in Server Actionsvercel · next.js · CWE-918 | Высокая7,5 | — | 5,5 % | 14 мая 2024 г. |
32Наблюдать | CVE-2026-64641Эксплойта нет | Next.js: Denial of Service in App Router using Server Actionsvercel · next.js · CWE-834 | Высокая8,2 | — | 0,9 % | 27 июл. 2026 г. |
32Наблюдать | CVE-2026-44574Эксплойта нет | Next.js: Middleware / Proxy bypass through dynamic route parameter injectionvercel · next.js · CWE-288 | Высокая8,1 | — | 0,7 % | 13 мая 2026 г. |
31Наблюдать | CVE-2024-51479Эксплойта нет | Authorization bypass in Next.jsvercel · next.js · CWE-285 | Высокая7,5 | — | 4,0 % | 17 дек. 2024 г. |
31Наблюдать | CVE-2022-21721Эксплойта нет | DOS Vulnerability in next.jsvercel · next.js | Высокая7,5 | — | 2,2 % | 28 янв. 2022 г. |
31Наблюдать | CVE-2022-23646Эксплойта нет | Improper CSP in Image Optimization API for Next.jsvercel · next.js · CWE-451 | Высокая7,5 | — | 1,8 % | 17 февр. 2022 г. |
31Наблюдать | CVE-2024-24828Эксплойта нет | Local Privilege Escalation in execuatables bundled by pkgvercel · pkg · CWE-276 | Высокая7,8 | — | 0,2 % | 9 февр. 2024 г. |
30Наблюдать | CVE-2023-46298Эксплойта нет | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a vercel · next.js | Высокая7,5 | — | 1,3 % | 21 окт. 2023 г. |
30Наблюдать | CVE-2024-34350Эксплойта нет | Next.js Vulnerable to HTTP Request Smugglingvercel · next.js · CWE-444 | Высокая7,5 | — | 1,2 % | 14 мая 2024 г. |
30Наблюдать | CVE-2025-49826Эксплойта нет | Next.js DoS vulnerability via cache poisoningvercel · next.js · CWE-444 | Высокая7,5 | — | 1,1 % | 3 июл. 2025 г. |
- CVE-2025-55182100Срочно
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %facebook · react3 дек. 2025 г.
- CVE-2025-2992766На этой неделе
Authorization Bypass in Next.js Middleware
КритическаяCVSS 9,1Готовый эксплойтEPSS 99 %vercel · next.js21 мар. 2025 г.
- CVE-2025-5518450В плане
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.
ВысокаяCVSS 7,5Proof of conceptEPSS 67 %facebook · react11 дек. 2025 г.
- CVE-2024-4698248В плане
Cache Poisoning in next.js
ВысокаяCVSS 7,5Proof of conceptEPSS 59 %vercel · next.js17 сент. 2024 г.
- CVE-2021-4380343В плане
Unexpected server crash in Next.js
ВысокаяCVSS 7,5Эксплойта нетEPSS 45 %vercel · next.js9 дек. 2021 г.
- CVE-2025-5518340В плане
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.
СредняяCVSS 5,3Proof of conceptEPSS 64 %vercel · next.js11 дек. 2025 г.
- CVE-2024-2374139Наблюдать
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeCliln
КритическаяCVSS 9,8Proof of conceptEPSS 2 %vercel · hyper27 янв. 2024 г.
- CVE-2025-6777936Наблюдать
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attac
ВысокаяCVSS 7,5Эксплойта нетEPSS 20 %facebook · react11 дек. 2025 г.
- CVE-2026-4457835Наблюдать
Next.js: Server-side request forgery in applications using WebSocket upgrades
ВысокаяCVSS 8,6Proof of conceptEPSS 2 %vercel · next.js13 мая 2026 г.
- CVE-2025-5782233Наблюдать
Next.js Improper Middleware Redirect Handling Leads to SSRF
ВысокаяCVSS 8,2Proof of conceptEPSS 2 %vercel · next.js29 авг. 2025 г.
- CVE-2026-6464233Наблюдать
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %vercel · next.js27 июл. 2026 г.
- CVE-2026-6464933Наблюдать
Next.js: Server-Side Request Forgery in Server Actions on Custom Servers
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %vercel · next.js27 июл. 2026 г.
- CVE-2026-6464533Наблюдать
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %vercel · next.js27 июл. 2026 г.
- CVE-2026-4650833Наблюдать
Turborepo: VSCode Extension command injection
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %vercel · turborepo language server protocol15 мая 2026 г.
- CVE-2015-831532Наблюдать
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "re
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %vercel · ms23 янв. 2017 г.
- CVE-2024-3435132Наблюдать
Next.js Server-Side Request Forgery in Server Actions
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %vercel · next.js14 мая 2024 г.
- CVE-2026-6464132Наблюдать
Next.js: Denial of Service in App Router using Server Actions
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %vercel · next.js27 июл. 2026 г.
- CVE-2026-4457432Наблюдать
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %vercel · next.js13 мая 2026 г.
- CVE-2024-5147931Наблюдать
Authorization bypass in Next.js
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %vercel · next.js17 дек. 2024 г.
- CVE-2022-2172131Наблюдать
DOS Vulnerability in next.js
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vercel · next.js28 янв. 2022 г.
- CVE-2022-2364631Наблюдать
Improper CSP in Image Optimization API for Next.js
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %vercel · next.js17 февр. 2022 г.
- CVE-2024-2482831Наблюдать
Local Privilege Escalation in execuatables bundled by pkg
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %vercel · pkg9 февр. 2024 г.
- CVE-2023-4629830Наблюдать
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vercel · next.js21 окт. 2023 г.
- CVE-2024-3435030Наблюдать
Next.js Vulnerable to HTTP Request Smuggling
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vercel · next.js14 мая 2024 г.
- CVE-2025-4982630Наблюдать
Next.js DoS vulnerability via cache poisoning
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vercel · next.js3 июл. 2025 г.