Vulnerability index

Browse CVEs

58 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-59472 A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume end… Next.js 15.6.0 / 16.1.5+ Fix from $1,9502026-01-26 HIGH 7.5 CVE-2025-59471 A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image… Next.js 15.5.10 / 16.1.5+ Fix from $1,9502026-01-26 MEDIUM 5.3 CVE-2025-48985 A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filet… Ai 5.0.52+ Fix from $1,6002025-11-07 HIGH 8.2 CVE-2025-57822 Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly … Next.js 14.2.32 / 15.4.7+ Fix from $1,9502025-08-29 MEDIUM 6.2 CVE-2025-57752 Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Opt… Next.js 14.2.31 / 15.4.5+ Fix from $1,6002025-08-29 HIGH 7.5 CVE-2025-7074 A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the f… Hyper after 3.4.1 Fix from $1,9502025-07-05 HIGH 7.5 CVE-2025-49826 Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading… Next.js 15.1.8+ Fix from $1,9502025-07-03 MEDIUM 5.9 CVE-2025-30218 Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id w… Next.js Mitigation only Fix from $1,6002025-04-02 CRITICAL 9.1 CVE-2025-29927EPSS 99% Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and … Next.js 12.3.5 / 13.5.9+ Fix from $2,3002025-03-21 MEDIUM 5.3 CVE-2024-56332 Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, … Next.js 13.5.8 / 14.2.21+ Fix from $1,6002025-01-03 HIGH 7.5 CVE-2024-51479 Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m… Next.js 14.2.15+ Fix from $1,9502024-12-17 HIGH 7.5 CVE-2024-47831 Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in … Next.js 14.2.7+ Fix from $1,9502024-10-14 HIGH 7.5 CVE-2024-46982EPSS 59% Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non… Next.js 13.5.7 / 14.2.10+ Fix from $1,9502024-09-17 HIGH 7.5 CVE-2024-39693 Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting t… Next.js 13.5.0+ Fix from $1,9502024-07-10 HIGH 7.5 CVE-2024-34351EPSS 5% Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was iden… Next.js 14.1.1+ Fix from $1,9502024-05-14 HIGH 7.5 CVE-2024-34350 Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafte… Next.js 13.5.1+ Fix from $1,9502024-05-14 HIGH 7.8 CVE-2024-24828 pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On u… Pkg after 5.8.1 Fix from $1,9502024-02-09 CRITICAL 9.8 CVE-2024-23741 An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArgu… Hyper after 3.4.1 Fix from $2,3002024-01-28 HIGH 7.5 CVE-2023-46298 Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of… Next.js 13.4.20+ Fix from $1,9502023-10-22 MEDIUM 5.3 CVE-2017-20162 A vulnerability, which was classified as problematic, has been found in vercel ms up to 1.x. This issue affects the function parse of the file index.… Ms 2.0.0+ Fix from $1,6002023-01-05 MEDIUM 5.3 CVE-2022-36046 Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CV… Next.js No fix yet Fix from $1,6002022-08-31 HIGH 7.5 CVE-2022-23646 Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentatio… Next.js 12.1.0+ Fix from $1,9502022-02-17 HIGH 7.5 CVE-2022-21721 Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial o… Next.js 12.0.9+ Fix from $1,9502022-01-28 HIGH 7.5 CVE-2021-43803EPSS 45% Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to b… Next.js 11.1.3 / 12.0.5+ Fix from $1,9502021-12-10 MEDIUM 6.1 CVE-2021-39178 Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to… Next.js 11.1.1+ Fix from $1,6002021-08-31 MEDIUM 6.1 CVE-2021-37699 Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used… Next.js after 11.0.1 Fix from $1,6002021-08-12 MEDIUM 6.1 CVE-2020-15242 Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to all… Next.js 9.5.4+ Fix from $1,6002020-10-08 HIGH 7.5 CVE-2015-8315EPSS 7% The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular exp… Ms 0.7.1+ Fix from $1,9502017-01-23