Записи zeit
9 опубликованных записей вендора zeit.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-177 Improper Handling of URL Encoding (Hex Encoding)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-23 Relative Path Traversal1
- CWE-548 Exposure of Information Through Directory Listing1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2017-16877Proof of concept | ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive infzeit · next.js · CWE-22 | Высокая7,5 | — | 14,1 % | 17 нояб. 2017 г. |
33Наблюдать | CVE-2018-6184Proof of concept | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.zeit · next.js · CWE-22 | Высокая7,5 | — | 9,1 % | 24 янв. 2018 г. |
31Наблюдать | CVE-2019-5417Эксплойта нет | A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote servzeit · serve · CWE-22 | Высокая7,5 | — | 2,3 % | 21 мар. 2019 г. |
30Наблюдать | CVE-2020-5284Proof of concept | Directory Traversal in Next.js versions below 9.3.2zeit · next.js · CWE-23 | Средняя4,3 | — | 44,3 % | 30 мар. 2020 г. |
30Наблюдать | CVE-2019-5415Эксплойта нет | A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the vzeit · serve · CWE-548 | Высокая7,5 | — | 1,6 % | 21 мар. 2019 г. |
27Наблюдать | CVE-2018-3712Эксплойта нет | serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in pathzeit · serve · CWE-22 | Средняя6,5 | — | 1,8 % | 6 июн. 2018 г. |
24Наблюдать | CVE-2018-18282Эксплойта нет | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.zeit · next.js · CWE-79 | Средняя6,1 | — | 1,0 % | 12 окт. 2018 г. |
21Наблюдать | CVE-2018-3718Эксплойта нет | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.zeit · serve · CWE-177 | Средняя5,3 | — | 1,3 % | 6 июн. 2018 г. |
21Наблюдать | CVE-2018-3809Эксплойта нет | Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be izeit · serve · CWE-200 | Средняя5,3 | — | 1,0 % | 1 июн. 2018 г. |
- CVE-2017-1687734Наблюдать
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive inf
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %zeit · next.js17 нояб. 2017 г.
- CVE-2018-618433Наблюдать
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %zeit · next.js24 янв. 2018 г.
- CVE-2019-541731Наблюдать
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote serv
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %zeit · serve21 мар. 2019 г.
- CVE-2020-528430Наблюдать
Directory Traversal in Next.js versions below 9.3.2
СредняяCVSS 4,3Proof of conceptEPSS 44 %zeit · next.js30 мар. 2020 г.
- CVE-2019-541530Наблюдать
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the v
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %zeit · serve21 мар. 2019 г.
- CVE-2018-371227Наблюдать
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in path
СредняяCVSS 6,5Эксплойта нетEPSS 2 %zeit · serve6 июн. 2018 г.
- CVE-2018-1828224Наблюдать
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %zeit · next.js12 окт. 2018 г.
- CVE-2018-371821Наблюдать
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %zeit · serve6 июн. 2018 г.
- CVE-2018-380921Наблюдать
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be i
СредняяCVSS 5,3Эксплойта нетEPSS 1 %zeit · serve1 июн. 2018 г.