CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1

CVE-2026-90651 HIGH

Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verif…

CVSS 8.1 EPSS 0.21% Sep 12, 2026
CVE-2026-59725 HIGH

Socket.IO: Engine.IO Polling Transport Connection Exhaustion

CVSS 7.5 EPSS 0.64% Jul 8, 2026
npm
CVE-2026-59724 HIGH

Socket.IO: Engine.IO WebTransport SID DoS

CVSS 7.5 EPSS 0.61% Jul 8, 2026
npm
CVE-2026-33151 HIGH

socket.io allows an unbounded number of binary attachments

CVSS 8.7 EPSS 0.63% Mar 20, 2026
npm
CVE-2024-38355 MEDIUM

Unhandled 'error' event in socket.io

CVSS 6.9 EPSS 0.81% Jun 19, 2024
npm
CVE-2023-32695 MEDIUM

Insufficient validation when decoding a Socket.IO packet

CVSS 6.9 EPSS 1.06% May 27, 2023
npm
CVE-2023-31125 MEDIUM

Uncaught exception in engine.io

CVSS 6.5 EPSS 1.33% May 8, 2023
npm
CVE-2022-41940 HIGH

Uncaught exception in engine.io

CVSS 7.1 EPSS 2.07% Nov 22, 2022
npm
CVE-2022-2421 CRITICAL

Socket.io - Improper type validation in attachment parsing

CVSS 10.0 EPSS 1.27% Oct 25, 2022
npm
CVE-2022-25867 HIGH

NULL Pointer Dereference

CVSS 7.5 EPSS 1.60% Aug 2, 2022
CVE-2022-21676 HIGH

Uncaught Exception in engine.io

CVSS 7.5 EPSS 2.76% Jan 12, 2022
npm
CVE-2020-28481 MEDIUM

Insecure Defaults

CVSS 5.3 EPSS 0.73% Jan 19, 2021
npm
CVE-2020-36048 HIGH

yarnpkg-socket.io/engine.io: allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport

CVSS 7.5 EPSS 3.24% Jan 7, 2021
npm
CVE-2020-36049 HIGH

yarnpkg-socket.io-parser: a denial of service (memory consumption) via a large packet because a concatenation approach is used

CVSS 7.5 EPSS 2.64% Jan 7, 2021
npm
CVE-2017-16031 HIGH

Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to cre…

CVSS 7.5 EPSS 2.00% Jun 4, 2018
npm
CVE-2016-10536 MEDIUM

engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communication layer for Socket.…

CVSS 5.9 EPSS 1.01% May 31, 2018
npm

Showing 1 to 16 CVEs · page 1