Vulnerabilidades em Vercel
66 resultadosAnálise Vexday
Vercel possui apenas 2 vulnerabilidades registradas na base do Vexday, nenhuma delas sob ataque ativo ou classificada como crítica, representando um perfil de risco baixo. A fraqueza dominante é relacionada a validação de entrada (CWE-20), mas sem atividade recente de publicações, indicando que o cenário de risco permanece estável e não apresenta exposições imediatas.
CVE-2025-29927CRITICALAuthorization Bypass in Next.js MiddlewareEPSS 99.2%CVE-2024-46982HIGHCache Poisoning in next.jsEPSS 59.2%CVE-2021-43803HIGHUnexpected server crash in Next.jsEPSS 44.8%CVE-2026-44578HIGHNext.js: Server-side request forgery in applications using WebSocket upgradesEPSS 38.9%CVE-2024-34351HIGHNext.js Server-Side Request Forgery in Server ActionsEPSS 5.5%CVE-2026-8767LOWvercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injectionEPSS 4.3%CVE-2024-51479HIGHAuthorization bypass in Next.jsEPSS 4.0%CVE-2025-57822MEDIUMNext.js Improper Middleware Redirect Handling Leads to SSRFEPSS 2.5%CVE-2026-75604CRITICALNext.js: Unauthenticated Remote Code Execution on windows-hosted serversEPSS 2.5%CVE-2022-23646MEDIUMImproper CSP in Image Optimization API for Next.jsEPSS 1.8%CVE-2026-44575HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesEPSS 1.6%CVE-2026-64641HIGHNext.js: Denial of Service in App Router using Server ActionsEPSS 1.4%CVE-2024-34350HIGHNext.js Vulnerable to HTTP Request SmugglingEPSS 1.2%CVE-2026-64642HIGHNext.js: Middleware / Proxy bypass in App Router applications using Turbopack and single localeEPSS 1.2%CVE-2022-36046MEDIUMUnexpected server crash in Next.js version 12.2.3EPSS 1.2%CVE-2021-39178HIGHXSS in Image Optimization API for Next.js versions between 10.0.0 and 11.1.0EPSS 1.1%CVE-2025-49826HIGHNext.js DoS vulnerability via cache poisoningEPSS 1.1%CVE-2021-37699MEDIUMOpen Redirect in Next.js versions below 11.1.0EPSS 1.0%CVE-2017-20162MEDIUMvercel ms index.js parse redosEPSS 1.0%CVE-2026-64649HIGHNext.js: Server-Side Request Forgery in Server Actions on Custom ServersEPSS 0.9%