zeit
Top products
Latest CVEs
The 9 most recently published vulnerabilities affecting zeit.
- CVE-2020-5284Directory Traversal in Next.js versions below 9.3.24.4
- CVE-2019-5415A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.7.5
- CVE-2019-5417A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.7.5
- CVE-2018-18282Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.6.1
- CVE-2018-3712serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of ...6.5
- CVE-2018-3718serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.5.3
- CVE-2018-3809Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.5.3
- CVE-2018-6184ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.7.5
- CVE-2017-16877ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.7.5