vercel kayıtları
vercel üreticisine ait 69 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,4
- Silahlaştırılmış
- 2 · %2,9
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %92,8
- Yayından KEV’e ortanca
- 2 gün
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption6
- CWE-770 Allocation of Resources Without Limits or Throttling5
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-502 Deserialization of Untrusted Data4
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')4
- CWE-288 Authentication Bypass Using an Alternate Path or Channel3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
69 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2025-55182Silahlaştırılmış | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclufacebook · react · CWE-502 | Kritik10,0 | KEV | %99,8 | 3 Ara 2025 |
66Bu hafta | CVE-2025-29927Silahlaştırılmış | Authorization Bypass in Next.js Middlewarevercel · next.js · CWE-285 | Kritik9,1 | — | %99,2 | 21 Mar 2025 |
50Planlayın | CVE-2025-55184Kavram kanıtı | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.facebook · react · CWE-502 | Yüksek7,5 | — | %66,9 | 11 Ara 2025 |
48Planlayın | CVE-2024-46982Kavram kanıtı | Cache Poisoning in next.jsvercel · next.js · CWE-639 | Yüksek7,5 | — | %59,2 | 17 Eyl 2024 |
43Planlayın | CVE-2021-43803İstismar yok | Unexpected server crash in Next.jsvercel · next.js · CWE-20 | Yüksek7,5 | — | %44,8 | 9 Ara 2021 |
40Planlayın | CVE-2025-55183Kavram kanıtı | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.vercel · next.js · CWE-502 | Orta5,3 | — | %64,2 | 11 Ara 2025 |
39İzleyin | CVE-2024-23741Kavram kanıtı | An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnvercel · hyper · CWE-94 | Kritik9,8 | — | %1,6 | 27 Oca 2024 |
36İzleyin | CVE-2025-67779İstismar yok | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attacfacebook · react · CWE-502 | Yüksek7,5 | — | %20,0 | 11 Ara 2025 |
35İzleyin | CVE-2026-44578Kavram kanıtı | Next.js: Server-side request forgery in applications using WebSocket upgradesvercel · next.js · CWE-918 | Yüksek8,6 | — | %1,9 | 13 May 2026 |
33İzleyin | CVE-2025-57822Kavram kanıtı | Next.js Improper Middleware Redirect Handling Leads to SSRFvercel · next.js · CWE-918 | Yüksek8,2 | — | %2,5 | 29 Ağu 2025 |
33İzleyin | CVE-2026-64642İstismar yok | Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localevercel · next.js · CWE-285 | Yüksek8,3 | — | %0,6 | 27 Tem 2026 |
33İzleyin | CVE-2026-64649İstismar yok | Next.js: Server-Side Request Forgery in Server Actions on Custom Serversvercel · next.js · CWE-918 | Yüksek8,3 | — | %0,5 | 27 Tem 2026 |
33İzleyin | CVE-2026-64645İstismar yok | Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostnamevercel · next.js · CWE-601 | Yüksek8,3 | — | %0,4 | 27 Tem 2026 |
33İzleyin | CVE-2026-46508İstismar yok | Turborepo: VSCode Extension command injectionvercel · turborepo language server protocol · CWE-77 | Yüksek8,4 | — | %0,2 | 15 May 2026 |
32İzleyin | CVE-2015-8315İstismar yok | The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "revercel · ms · CWE-1333 | Yüksek7,5 | — | %6,8 | 23 Oca 2017 |
32İzleyin | CVE-2024-34351Kavram kanıtı | Next.js Server-Side Request Forgery in Server Actionsvercel · next.js · CWE-918 | Yüksek7,5 | — | %5,5 | 14 May 2024 |
32İzleyin | CVE-2026-64641İstismar yok | Next.js: Denial of Service in App Router using Server Actionsvercel · next.js · CWE-834 | Yüksek8,2 | — | %0,9 | 27 Tem 2026 |
32İzleyin | CVE-2026-44574İstismar yok | Next.js: Middleware / Proxy bypass through dynamic route parameter injectionvercel · next.js · CWE-288 | Yüksek8,1 | — | %0,7 | 13 May 2026 |
31İzleyin | CVE-2024-51479İstismar yok | Authorization bypass in Next.jsvercel · next.js · CWE-285 | Yüksek7,5 | — | %4,0 | 17 Ara 2024 |
31İzleyin | CVE-2022-21721İstismar yok | DOS Vulnerability in next.jsvercel · next.js | Yüksek7,5 | — | %2,2 | 28 Oca 2022 |
31İzleyin | CVE-2022-23646İstismar yok | Improper CSP in Image Optimization API for Next.jsvercel · next.js · CWE-451 | Yüksek7,5 | — | %1,8 | 17 Şub 2022 |
31İzleyin | CVE-2024-24828İstismar yok | Local Privilege Escalation in execuatables bundled by pkgvercel · pkg · CWE-276 | Yüksek7,8 | — | %0,2 | 9 Şub 2024 |
30İzleyin | CVE-2023-46298İstismar yok | Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a vercel · next.js | Yüksek7,5 | — | %1,3 | 21 Eki 2023 |
30İzleyin | CVE-2024-34350İstismar yok | Next.js Vulnerable to HTTP Request Smugglingvercel · next.js · CWE-444 | Yüksek7,5 | — | %1,2 | 14 May 2024 |
30İzleyin | CVE-2025-49826İstismar yok | Next.js DoS vulnerability via cache poisoningvercel · next.js · CWE-444 | Yüksek7,5 | — | %1,1 | 3 Tem 2025 |
- CVE-2025-55182100Hemen
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 inclu
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100facebook · react3 Ara 2025
- CVE-2025-2992766Bu hafta
Authorization Bypass in Next.js Middleware
KritikCVSS 9,1SilahlaştırılmışEPSS %99vercel · next.js21 Mar 2025
- CVE-2025-5518450Planlayın
A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.2, 19.2.
YüksekCVSS 7,5Kavram kanıtıEPSS %67facebook · react11 Ara 2025
- CVE-2024-4698248Planlayın
Cache Poisoning in next.js
YüksekCVSS 7,5Kavram kanıtıEPSS %59vercel · next.js17 Eyl 2024
- CVE-2021-4380343Planlayın
Unexpected server crash in Next.js
YüksekCVSS 7,5İstismar yokEPSS %45vercel · next.js9 Ara 2021
- CVE-2025-5518340Planlayın
An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 19.1.0, 19.1.1, 19.1.
OrtaCVSS 5,3Kavram kanıtıEPSS %64vercel · next.js11 Ara 2025
- CVE-2024-2374139İzleyin
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeCliln
KritikCVSS 9,8Kavram kanıtıEPSS %2vercel · hyper27 Oca 2024
- CVE-2025-6777936İzleyin
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attac
YüksekCVSS 7,5İstismar yokEPSS %20facebook · react11 Ara 2025
- CVE-2026-4457835İzleyin
Next.js: Server-side request forgery in applications using WebSocket upgrades
YüksekCVSS 8,6Kavram kanıtıEPSS %2vercel · next.js13 May 2026
- CVE-2025-5782233İzleyin
Next.js Improper Middleware Redirect Handling Leads to SSRF
YüksekCVSS 8,2Kavram kanıtıEPSS %2vercel · next.js29 Ağu 2025
- CVE-2026-6464233İzleyin
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
YüksekCVSS 8,3İstismar yokEPSS %1vercel · next.js27 Tem 2026
- CVE-2026-6464933İzleyin
Next.js: Server-Side Request Forgery in Server Actions on Custom Servers
YüksekCVSS 8,3İstismar yokEPSS %0vercel · next.js27 Tem 2026
- CVE-2026-6464533İzleyin
Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
YüksekCVSS 8,3İstismar yokEPSS %0vercel · next.js27 Tem 2026
- CVE-2026-4650833İzleyin
Turborepo: VSCode Extension command injection
YüksekCVSS 8,4İstismar yokEPSS %0vercel · turborepo language server protocol15 May 2026
- CVE-2015-831532İzleyin
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "re
YüksekCVSS 7,5İstismar yokEPSS %7vercel · ms23 Oca 2017
- CVE-2024-3435132İzleyin
Next.js Server-Side Request Forgery in Server Actions
YüksekCVSS 7,5Kavram kanıtıEPSS %5vercel · next.js14 May 2024
- CVE-2026-6464132İzleyin
Next.js: Denial of Service in App Router using Server Actions
YüksekCVSS 8,2İstismar yokEPSS %1vercel · next.js27 Tem 2026
- CVE-2026-4457432İzleyin
Next.js: Middleware / Proxy bypass through dynamic route parameter injection
YüksekCVSS 8,1İstismar yokEPSS %1vercel · next.js13 May 2026
- CVE-2024-5147931İzleyin
Authorization bypass in Next.js
YüksekCVSS 7,5İstismar yokEPSS %4vercel · next.js17 Ara 2024
- CVE-2022-2172131İzleyin
DOS Vulnerability in next.js
YüksekCVSS 7,5İstismar yokEPSS %2vercel · next.js28 Oca 2022
- CVE-2022-2364631İzleyin
Improper CSP in Image Optimization API for Next.js
YüksekCVSS 7,5İstismar yokEPSS %2vercel · next.js17 Şub 2022
- CVE-2024-2482831İzleyin
Local Privilege Escalation in execuatables bundled by pkg
YüksekCVSS 7,8İstismar yokEPSS %0vercel · pkg9 Şub 2024
- CVE-2023-4629830İzleyin
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a
YüksekCVSS 7,5İstismar yokEPSS %1vercel · next.js21 Eki 2023
- CVE-2024-3435030İzleyin
Next.js Vulnerable to HTTP Request Smuggling
YüksekCVSS 7,5İstismar yokEPSS %1vercel · next.js14 May 2024
- CVE-2025-4982630İzleyin
Next.js DoS vulnerability via cache poisoning
YüksekCVSS 7,5İstismar yokEPSS %1vercel · next.js3 Tem 2025