Количество 191
Количество 191
GHSA-g77x-44xx-532m
Denial of Service condition in Next.js image optimization
GHSA-g5qg-72qw-gw5v
Next.js Affected by Cache Key Confusion for Image Optimization API Routes
GHSA-fr5h-rqp8-mj6g
Next.js Server-Side Request Forgery in Server Actions
GHSA-fq77-7p7r-83rj
Directory Traversal in Next.js
GHSA-fq54-2j52-jc42
Next.js Denial of Service (DoS) condition
GHSA-fmvm-x8mv-47mj
Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0
GHSA-ffhc-5mcf-pf4q
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces
GHSA-f82v-jwr5-mffw
Authorization Bypass in Next.js Middleware
GHSA-c59h-r6p8-q9wc
Next.js missing cache-control header may lead to CDN caching empty reply
GHSA-c4j6-fc7j-m34r
Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades
GHSA-9gr3-7897-pp7m
XSS in Image Optimization API for Next.js
GHSA-9g9p-9gw9-jx7f
Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration
GHSA-955p-x3mx-jcvp
Next.js: Unauthenticated disclosure of internal Server Function endpoints
GHSA-89xv-2m56-2m9x
Next.js: Server-Side Request Forgery in Server Actions on custom servers
GHSA-7m27-7ghc-44w9
Next.js Allows a Denial of Service (DoS) with Server Actions
GHSA-7gfc-8cq8-jh5f
Next.js authorization bypass vulnerability
GHSA-77r5-gw3j-2mpf
Next.js Vulnerable to HTTP Request Smuggling
GHSA-6gpp-xcg3-4w24
Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
GHSA-68g3-v927-f742
Next.js: Cache confusion of response bodies for requests with bodies
GHSA-67rr-84xm-4c7r
Next.JS vulnerability can lead to DoS via cache poisoning
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-g77x-44xx-532m Denial of Service condition in Next.js image optimization | CVSS3: 5.9 | 1% Низкий | почти 2 года назад | |
GHSA-g5qg-72qw-gw5v Next.js Affected by Cache Key Confusion for Image Optimization API Routes | CVSS3: 6.2 | 0% Низкий | около 1 года назад | |
GHSA-fr5h-rqp8-mj6g Next.js Server-Side Request Forgery in Server Actions | CVSS3: 7.5 | 5% Низкий | больше 2 лет назад | |
GHSA-fq77-7p7r-83rj Directory Traversal in Next.js | CVSS3: 4.4 | 44% Средний | больше 6 лет назад | |
GHSA-fq54-2j52-jc42 Next.js Denial of Service (DoS) condition | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-fmvm-x8mv-47mj Improper CSP in Image Optimization API for Next.js versions between 10.0.0 and 12.1.0 | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
GHSA-ffhc-5mcf-pf4q Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
GHSA-f82v-jwr5-mffw Authorization Bypass in Next.js Middleware | CVSS3: 9.1 | 99% Критический | больше 1 года назад | |
GHSA-c59h-r6p8-q9wc Next.js missing cache-control header may lead to CDN caching empty reply | 1% Низкий | почти 3 года назад | ||
GHSA-c4j6-fc7j-m34r Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades | CVSS3: 8.6 | 39% Средний | 4 месяца назад | |
GHSA-9gr3-7897-pp7m XSS in Image Optimization API for Next.js | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
GHSA-9g9p-9gw9-jx7f Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration | CVSS3: 5.9 | 0% Низкий | 8 месяцев назад | |
GHSA-955p-x3mx-jcvp Next.js: Unauthenticated disclosure of internal Server Function endpoints | 1% Низкий | около 2 месяцев назад | ||
GHSA-89xv-2m56-2m9x Next.js: Server-Side Request Forgery in Server Actions on custom servers | 1% Низкий | около 2 месяцев назад | ||
GHSA-7m27-7ghc-44w9 Next.js Allows a Denial of Service (DoS) with Server Actions | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
GHSA-7gfc-8cq8-jh5f Next.js authorization bypass vulnerability | CVSS3: 7.5 | 4% Низкий | больше 1 года назад | |
GHSA-77r5-gw3j-2mpf Next.js Vulnerable to HTTP Request Smuggling | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-6gpp-xcg3-4w24 Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale | 1% Низкий | около 2 месяцев назад | ||
GHSA-68g3-v927-f742 Next.js: Cache confusion of response bodies for requests with bodies | 0% Низкий | около 2 месяцев назад | ||
GHSA-67rr-84xm-4c7r Next.JS vulnerability can lead to DoS via cache poisoning | CVSS3: 7.5 | 1% Низкий | около 1 года назад |
Уязвимостей на страницу