Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Moderate

CVE-2020-5284

Disclosure Date: March 30, 2020 (last updated February 21, 2025)
Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.
Attacker Value
Unknown

CVE-2019-5415

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.
Attacker Value
Unknown

CVE-2019-5417

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.
0
Attacker Value
Unknown

CVE-2018-18282

Disclosure Date: October 12, 2018 (last updated November 27, 2024)
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
0
Attacker Value
Unknown

CVE-2018-3712

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.
0
Attacker Value
Unknown

CVE-2018-3718

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Attacker Value
Unknown

CVE-2018-3809

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.
0
Attacker Value
Unknown

CVE-2018-6184

Disclosure Date: January 24, 2018 (last updated November 26, 2024)
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
0
Attacker Value
Unknown

CVE-2017-16877

Disclosure Date: November 17, 2017 (last updated December 08, 2023)
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2014-6910

Disclosure Date: October 04, 2014 (last updated October 05, 2023)
The MemorizeIt! (aka com.kshinenterprises.kshinent.memorizeit) application 1.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0