Known Vulnerabilities for products from Zeit

Listed below are 9 of the newest known vulnerabilities associated with the vendor "Zeit".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2020-5284 json Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access file... 4.3 - MEDIUM 2020-03-30 2020-04-01
CVE-2019-5417 json A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on ... 7.5 - HIGH 2019-03-21 2019-03-25
CVE-2019-5415 json A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the direc... 7.5 - HIGH 2019-03-21 2020-10-19
CVE-2018-18282 json Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. 6.1 - MEDIUM 2018-10-12 2018-11-28
CVE-2018-6184 json ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. 7.5 - HIGH 2018-01-24 2018-02-12
CVE-2018-3809 json Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have b... 5.3 - MEDIUM 2018-06-01 2018-07-17
CVE-2018-3718 json serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL e... 5.3 - MEDIUM 2018-06-07 2023-02-28
CVE-2018-3712 json serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowi... 6.5 - MEDIUM 2018-06-07 2019-10-09
CVE-2017-16877 json ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtai... Not Provided 2017-11-17 2025-04-20

Known software with vulnerabilities from Zeit

Type Vendor Product Version
ApplicationZeitNext.js1.0.0
ApplicationZeitServe0.1.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report