Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-5415
A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has…
Serve
No fix yet
HIGH 7.5
CVE-2019-5417
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.
Serve
7.3.1+
MEDIUM 6.1
CVE-2018-18282
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
Next.js
Mitigation only
MEDIUM 5.3
CVE-2018-3718
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Serve
6.5.2+
MEDIUM 6.5
CVE-2018-3712
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which …
Serve
6.4.9+
MEDIUM 5.3
CVE-2018-3809
Information exposure through directory listings in serve 6.5.3 allows directory listing and file access even when they have been set to be ignored.
Serve
No fix yet
HIGH 7.5
CVE-2018-6184EPSS 9%
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
Next.js
Mitigation only
HIGH 7.5
CVE-2017-16877EPSS 14%
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
Next.js
2.4.1+