Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Moderate
CVE-2020-5284
Disclosure Date: March 30, 2020 (last updated February 21, 2025)
Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.
1
Attacker Value
Unknown
CVE-2019-5415
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.
0
Attacker Value
Unknown
CVE-2019-5417
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.
0
Attacker Value
Unknown
CVE-2018-18282
Disclosure Date: October 12, 2018 (last updated November 27, 2024)
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
0
Attacker Value
Unknown
CVE-2018-3712
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.
0
Attacker Value
Unknown
CVE-2018-3718
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
0
Attacker Value
Unknown
CVE-2018-3809
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.
0
Attacker Value
Unknown
CVE-2018-6184
Disclosure Date: January 24, 2018 (last updated November 26, 2024)
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
0
Attacker Value
Unknown
CVE-2017-16877
Disclosure Date: November 17, 2017 (last updated December 08, 2023)
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2014-6910
Disclosure Date: October 04, 2014 (last updated October 05, 2023)
The MemorizeIt! (aka com.kshinenterprises.kshinent.memorizeit) application 1.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0