Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-59472
A denial of service vulnerability exists in Next.js versions with Partial Prerendering (PPR) enabled when running in minimal mode. The PPR resume end…
Next.js
15.6.0 / 16.1.5+
HIGH 7.5
CVE-2025-59471
A denial of service vulnerability exists in self-hosted Next.js applications that have `remotePatterns` configured for the Image Optimizer. The image…
Next.js
15.5.10 / 16.1.5+
MEDIUM 5.3
CVE-2025-48985
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filet…
Ai
5.0.52+
HIGH 8.2
CVE-2025-57822
Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next() was used without explicitly …
Next.js
14.2.32 / 15.4.7+
MEDIUM 6.2
CVE-2025-57752
Next.js is a React framework for building full-stack web applications. In versions before 14.2.31 and from 15.0.0 to before 15.4.5, Next.js Image Opt…
Next.js
14.2.31 / 15.4.5+
HIGH 7.5
CVE-2025-7074
A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the f…
Hyper
after 3.4.1
HIGH 7.5
CVE-2025-49826
Next.js is a React framework for building full-stack web applications. From versions 15.0.4-canary.51 to before 15.1.8, a cache poisoning bug leading…
Next.js
15.1.8+
MEDIUM 5.9
CVE-2025-30218
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id w…
Next.js
Mitigation only
CRITICAL 9.1
CVE-2025-29927EPSS 99%
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …
Next.js
12.3.5 / 13.5.9+
MEDIUM 5.3
CVE-2024-56332
Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions 13.5.8, 14.2.21, and 15.1.2, …
Next.js
13.5.8 / 14.2.21+
HIGH 7.5
CVE-2024-51479
Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in m…
Next.js
14.2.15+
HIGH 7.5
CVE-2024-47831
Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in …
Next.js
14.2.7+
HIGH 7.5
CVE-2024-46982EPSS 59%
Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a non…
Next.js
13.5.7 / 14.2.10+
HIGH 7.5
CVE-2024-39693
Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting t…
Next.js
13.5.0+
HIGH 7.5
CVE-2024-34351EPSS 5%
Next.js is a React framework that can provide building blocks to create web applications. A Server-Side Request Forgery (SSRF) vulnerability was iden…
Next.js
14.1.1+
HIGH 7.5
CVE-2024-34350
Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafte…
Next.js
13.5.1+
HIGH 7.8
CVE-2024-24828
pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On u…
Pkg
after 5.8.1
CRITICAL 9.8
CVE-2024-23741
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArgu…
Hyper
after 3.4.1
HIGH 7.5
CVE-2023-46298
Next.js before 13.4.20-canary.13 lacks a cache-control header and thus empty prefetch responses may sometimes be cached by a CDN, causing a denial of…
Next.js
13.4.20+
MEDIUM 5.3
CVE-2017-20162
A vulnerability, which was classified as problematic, has been found in vercel ms up to 1.x. This issue affects the function parse of the file index.…
Ms
2.0.0+
MEDIUM 5.3
CVE-2022-36046
Next.js is a React framework that can provide building blocks to create web applications. All of the following must be true to be affected by this CV…
Next.js
No fix yet
HIGH 7.5
CVE-2022-23646
Next.js is a React framework. Starting with version 10.0.0 and prior to version 12.1.0, Next.js is vulnerable to User Interface (UI) Misrepresentatio…
Next.js
12.1.0+
HIGH 7.5
CVE-2022-21721
Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a bad actor to trigger a denial o…
Next.js
12.0.9+
HIGH 7.5
CVE-2021-43803EPSS 45%
Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to b…
Next.js
11.1.3 / 12.0.5+
MEDIUM 6.1
CVE-2021-39178
Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability. In order for an instance to…
Next.js
11.1.1+
MEDIUM 6.1
CVE-2021-37699
Next.js is an open source website development framework to be used with the React library. In affected versions specially encoded paths could be used…
Next.js
after 11.0.1
MEDIUM 6.1
CVE-2020-15242
Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to all…
Next.js
9.5.4+
HIGH 7.5
CVE-2015-8315EPSS 7%
The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular exp…
Ms
0.7.1+