Known Vulnerabilities for products from Zeit
Listed below are 9 of the newest known vulnerabilities associated with the vendor "Zeit".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-5284 json | Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access file... | 4.3 - MEDIUM | 2020-03-30 | 2020-04-01 |
| CVE-2019-5417 json | A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on ... | 7.5 - HIGH | 2019-03-21 | 2019-03-25 |
| CVE-2019-5415 json | A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the direc... | 7.5 - HIGH | 2019-03-21 | 2020-10-19 |
| CVE-2018-18282 json | Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. | 6.1 - MEDIUM | 2018-10-12 | 2018-11-28 |
| CVE-2018-6184 json | ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. | 7.5 - HIGH | 2018-01-24 | 2018-02-12 |
| CVE-2018-3809 json | Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have b... | 5.3 - MEDIUM | 2018-06-01 | 2018-07-17 |
| CVE-2018-3718 json | serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL e... | 5.3 - MEDIUM | 2018-06-07 | 2023-02-28 |
| CVE-2018-3712 json | serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowi... | 6.5 - MEDIUM | 2018-06-07 | 2019-10-09 |
| CVE-2017-16877 json | ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtai... | Not Provided | 2017-11-17 | 2025-04-20 |