CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verif…
Socket.IO: Engine.IO Polling Transport Connection Exhaustion
Socket.IO: Engine.IO WebTransport SID DoS
socket.io allows an unbounded number of binary attachments
Unhandled 'error' event in socket.io
Insufficient validation when decoding a Socket.IO packet
Uncaught exception in engine.io
Uncaught exception in engine.io
Socket.io - Improper type validation in attachment parsing
NULL Pointer Dereference
Uncaught Exception in engine.io
Insecure Defaults
yarnpkg-socket.io/engine.io: allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport
yarnpkg-socket.io-parser: a denial of service (memory consumption) via a large packet because a concatenation approach is used
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to cre…
engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.…
Showing 1 to 16 CVEs · page 1