Zeit
3 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.
Zeit CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2018-06 | 3 | 0 |
Products
The products that kept showing up in Zeit's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Zeit.
- CVE-2020-5284Directory Traversal in Next.js versions below 9.3.24.4
- CVE-2019-5415A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.7.5
- CVE-2019-5417A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.7.5
- CVE-2018-18282Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.6.1
- CVE-2018-3712serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of ...6.5
- CVE-2018-3718serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.5.3
- CVE-2018-3809Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.5.3
- CVE-2018-6184ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.7.5
- CVE-2017-16877ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.7.5
The record
- Peak rank
- #149 in Jun 2018
- Busiest month shown
- Jun 2018, 3 CVEs
- Months with a KEV entry
- 0 since Jun 2018
- Monthly snapshots
- 1 since 2018