Skip to content
Noroxi

Socket records

15 published records for vendor socket.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

15 records
  • CVE-2022-2421
    39Monitor

    Socket.io - Improper type validation in attachment parsing

    CriticalCVSS 9.8No exploitEPSS 1%

    socket · socket.io-parserOct 26, 2022

  • socket.io allows an unbounded number of binary attachments

    HighCVSS 8.7No exploitEPSS 1%

    socket · socket.io-parserMar 20, 2026

  • Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport

    HighCVSS 7.5No exploitEPSS 3%

    socket · engine.ioJan 7, 2021

  • Uncaught Exception in engine.io

    HighCVSS 7.5No exploitEPSS 3%

    socket · engine.ioJan 12, 2022

  • socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation

    HighCVSS 7.5No exploitEPSS 3%

    socket · socket.io-parserJan 7, 2021

  • Socket.io is a realtime application framework that provides communication via websockets.

    HighCVSS 7.5No exploitEPSS 2%

    socket · socket.ioJun 4, 2018

  • NULL Pointer Dereference

    HighCVSS 7.5No exploitEPSS 2%

    socket · socket.io-client javaAug 2, 2022

  • Insufficient validation when decoding a Socket.IO packet

    HighCVSS 7.5No exploitEPSS 1%

    socket · socket.io-parserMay 27, 2023

  • Socket.IO: Engine.IO Polling Transport Connection Exhaustion

    HighCVSS 7.5No exploitEPSS 1%

    socket · engine.ioJul 8, 2026

  • Socket.IO: Engine.IO WebTransport SID DoS

    HighCVSS 7.5No exploitEPSS 1%

    socket · engine.ioJul 8, 2026

  • Unhandled 'error' event in socket.io

    HighCVSS 7.3Proof of conceptEPSS 1%

    socketio · socket.ioJun 19, 2024

  • Uncaught exception in engine.io

    MediumCVSS 6.5No exploitEPSS 2%

    socket · engine.ioNov 21, 2022

  • Uncaught exception in engine.io

    MediumCVSS 6.5No exploitEPSS 1%

    socket · engine.ioMay 8, 2023

  • engine.io-client is the client for engine.io, the implementation of a transport-based cross-browser/cross-device bi-directional communicatio

    MediumCVSS 5.9No exploitEPSS 1%

    socket · engine.io-clientMay 31, 2018

  • The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration.

    MediumCVSS 4.3No exploitEPSS 1%

    socket · socket.ioJan 19, 2021