ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-5284
Next.js versions before 9.3.2 have a directory traversal vulnerability.

Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.

NVD description · AI analysis pending
4.344%
  • zeit next.js
CVE-2019-5417
+1 in the same advisory: …5415
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.

A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.

NVD description · AI analysis pending
7.52% PoC
  • zeit serve
CVE-2018-18282
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.

Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.

NVD description · AI analysis pending
6.11%
  • zeit next.js
CVE-2018-3712
+1 in the same advisory: …3718
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a ma

serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.

NVD description · AI analysis pending
6.5
group max
2% PoC
  • zeit serve
CVE-2018-3809
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.

Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.

NVD description · AI analysis pending
5.31% PoC
  • zeit serve
CVE-2018-6184
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

NVD description · AI analysis pending
7.59%
  • zeit next.js
CVE-2017-16877
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

NVD description · AI analysis pending
7.514%
  • zeit next.js