Vulnerability index

Browse CVEs

58 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Next.js HIGH 7.5
CVE-2025-59472

A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume end…

Fix: 15.6.0 / 16.1.5+
Fix from $1,950 2026-01-26
Next.js HIGH 7.5
CVE-2025-59471

A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image…

Fix: 15.5.10 / 16.1.5+
Fix from $1,950 2026-01-26
Ai MEDIUM 5.3
CVE-2025-48985

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filet…

Fix: 5.0.52+
Fix from $1,600 2025-11-07
Next.js HIGH 8.2
CVE-2025-57822

Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly …

Fix: 14.2.32 / 15.4.7+
Fix from $1,950 2025-08-29
Next.js MEDIUM 6.2
CVE-2025-57752

Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Opt…

Fix: 14.2.31 / 15.4.5+
Fix from $1,600 2025-08-29
Hyper HIGH 7.5
CVE-2025-7074

A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the f…

Fix: after 3.4.1
Fix from $1,950 2025-07-05
Next.js HIGH 7.5
CVE-2025-49826

Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading…

Fix: 15.1.8+
Fix from $1,950 2025-07-03
Next.js MEDIUM 5.9
CVE-2025-30218

Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id w…

Mitigation only
Fix from $1,600 2025-04-02
Next.js CRITICAL 9.1
CVE-2025-29927EPSS 99%

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …

Fix: 12.3.5 / 13.5.9+
Fix from $2,300 2025-03-21
Next.js MEDIUM 5.3
CVE-2024-56332

Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, …

Fix: 13.5.8 / 14.2.21+
Fix from $1,600 2025-01-03
Next.js HIGH 7.5
CVE-2024-51479

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m…

Fix: 14.2.15+
Fix from $1,950 2024-12-17
Next.js HIGH 7.5
CVE-2024-47831

Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in …

Fix: 14.2.7+
Fix from $1,950 2024-10-14
Next.js HIGH 7.5
CVE-2024-46982EPSS 59%

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non…

Fix: 13.5.7 / 14.2.10+
Fix from $1,950 2024-09-17
Next.js HIGH 7.5
CVE-2024-39693

Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting t…

Fix: 13.5.0+
Fix from $1,950 2024-07-10
Next.js HIGH 7.5
CVE-2024-34351EPSS 5%

Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was iden…

Fix: 14.1.1+
Fix from $1,950 2024-05-14
Next.js HIGH 7.5
CVE-2024-34350

Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafte…

Fix: 13.5.1+
Fix from $1,950 2024-05-14
Pkg HIGH 7.8
CVE-2024-24828

pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On u…

Fix: after 5.8.1
Fix from $1,950 2024-02-09
Hyper CRITICAL 9.8
CVE-2024-23741

An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArgu…

Fix: after 3.4.1
Fix from $2,300 2024-01-28
Next.js HIGH 7.5
CVE-2023-46298

Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of…

Fix: 13.4.20+
Fix from $1,950 2023-10-22
Ms MEDIUM 5.3
CVE-2017-20162

A vulnerability, which was classified as problematic, has been found in vercel ms up to 1.x. This issue affects the function parse of the file index.…

Fix: 2.0.0+
Fix from $1,600 2023-01-05
Next.js MEDIUM 5.3
CVE-2022-36046

Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CV…

No fix yet
Fix from $1,600 2022-08-31
Next.js HIGH 7.5
CVE-2022-23646

Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentatio…

Fix: 12.1.0+
Fix from $1,950 2022-02-17
Next.js HIGH 7.5
CVE-2022-21721

Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial o…

Fix: 12.0.9+
Fix from $1,950 2022-01-28
Next.js HIGH 7.5
CVE-2021-43803EPSS 45%

Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to b…

Fix: 11.1.3 / 12.0.5+
Fix from $1,950 2021-12-10
Next.js MEDIUM 6.1
CVE-2021-39178

Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to…

Fix: 11.1.1+
Fix from $1,600 2021-08-31
Next.js MEDIUM 6.1
CVE-2021-37699

Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used…

Fix: after 11.0.1
Fix from $1,600 2021-08-12
Next.js MEDIUM 6.1
CVE-2020-15242

Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to all…

Fix: 9.5.4+
Fix from $1,600 2020-10-08
Ms HIGH 7.5
CVE-2015-8315EPSS 7%

The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular exp…

Fix: 0.7.1+
Fix from $1,950 2017-01-23