CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
CVE-2025-47269 HIGH
code-server session cookie can be extracted by having user visit specially crafted proxy URL
CVSS 8.3 EPSS 42.69% May 9, 2025
npm
CVE-2023-26114 CRITICAL
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow…
CVSS 9.3 EPSS 0.34% Mar 23, 2023
npm
CVE-2021-42648 MEDIUM
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted URL.
CVSS 6.1 EPSS 0.87% May 11, 2022
npm
CVE-2021-3810 HIGH
Inefficient Regular Expression Complexity in cdr/code-server
CVSS 7.5 EPSS 1.26% Sep 17, 2021
npm
Showing 1 to 4 CVEs · page 1