zeit kayıtları
zeit üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-177 Improper Handling of URL Encoding (Hex Encoding)1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-23 Relative Path Traversal1
- CWE-548 Exposure of Information Through Directory Listing1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2017-16877Kavram kanıtı | ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive infzeit · next.js · CWE-22 | Yüksek7,5 | — | %14,1 | 17 Kas 2017 |
33İzleyin | CVE-2018-6184Kavram kanıtı | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.zeit · next.js · CWE-22 | Yüksek7,5 | — | %9,1 | 24 Oca 2018 |
31İzleyin | CVE-2019-5417İstismar yok | A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote servzeit · serve · CWE-22 | Yüksek7,5 | — | %2,3 | 21 Mar 2019 |
30İzleyin | CVE-2020-5284Kavram kanıtı | Directory Traversal in Next.js versions below 9.3.2zeit · next.js · CWE-23 | Orta4,3 | — | %44,3 | 30 Mar 2020 |
30İzleyin | CVE-2019-5415İstismar yok | A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the vzeit · serve · CWE-548 | Yüksek7,5 | — | %1,6 | 21 Mar 2019 |
27İzleyin | CVE-2018-3712İstismar yok | serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in pathzeit · serve · CWE-22 | Orta6,5 | — | %1,8 | 6 Haz 2018 |
24İzleyin | CVE-2018-18282İstismar yok | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.zeit · next.js · CWE-79 | Orta6,1 | — | %1,0 | 12 Eki 2018 |
21İzleyin | CVE-2018-3718İstismar yok | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.zeit · serve · CWE-177 | Orta5,3 | — | %1,3 | 6 Haz 2018 |
21İzleyin | CVE-2018-3809İstismar yok | Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be izeit · serve · CWE-200 | Orta5,3 | — | %1,0 | 1 Haz 2018 |
- CVE-2017-1687734İzleyin
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive inf
YüksekCVSS 7,5Kavram kanıtıEPSS %14zeit · next.js17 Kas 2017
- CVE-2018-618433İzleyin
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
YüksekCVSS 7,5Kavram kanıtıEPSS %9zeit · next.js24 Oca 2018
- CVE-2019-541731İzleyin
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote serv
YüksekCVSS 7,5İstismar yokEPSS %2zeit · serve21 Mar 2019
- CVE-2020-528430İzleyin
Directory Traversal in Next.js versions below 9.3.2
OrtaCVSS 4,3Kavram kanıtıEPSS %44zeit · next.js30 Mar 2020
- CVE-2019-541530İzleyin
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the v
YüksekCVSS 7,5İstismar yokEPSS %2zeit · serve21 Mar 2019
- CVE-2018-371227İzleyin
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in path
OrtaCVSS 6,5İstismar yokEPSS %2zeit · serve6 Haz 2018
- CVE-2018-1828224İzleyin
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
OrtaCVSS 6,1İstismar yokEPSS %1zeit · next.js12 Eki 2018
- CVE-2018-371821İzleyin
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
OrtaCVSS 5,3İstismar yokEPSS %1zeit · serve6 Haz 2018
- CVE-2018-380921İzleyin
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be i
OrtaCVSS 5,3İstismar yokEPSS %1zeit · serve1 Haz 2018