All vulnerabilities
28 / 28
Sort
8.8
CVE-2024-48849
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not suf…
2024-01-01Pre-auth
EPSS0.9%
pct 54
8.8
CVE-2025-24964CVE
Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remot…
2025-01-01Pre-auth
EPSS0.6%
pct 45
6.1
CVE-2023-23602AST
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Securit…
2023-01-01Pre-auth
EPSS0.6%
pct 43
6.5
CVE-2025-68930ANC
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain a Cr…
2025-01-01Pre-auth
EPSS0.5%
pct 41
9.6
CVE-2023-0957CVE
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site…
2023-01-01Pre-auth
EPSS0.4%
pct 33
9.8
CVE-2024-23168
Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicio…
2024-01-01Pre-auth
EPSS0.4%
pct 32
9.8
CVE-2014-125071CVE
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected…
2014-01-01Pre-auth
EPSS0.4%
pct 31
8.8
CVE-2023-49805CVE
Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the applica…
2023-01-01
EPSS0.4%
pct 29
9.3
CVE-2023-26114CVE
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation i…
2023-01-01Pre-auth
EPSS0.3%
pct 25
8.8
CVE-2025-52882ANC
Claude Code is an agentic coding tool. Claude Code extensions in VSCode and forks (e.g., Cursor…
2025-01-01Pre-auth
EPSS0.3%
pct 23
8.8
CVE-2023-2848CVE
Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This…
2023-01-01Pre-auth
EPSS0.3%
pct 22
4.7
CVE-2023-2850CVE
NodeBB is affected by a Cross-Site WebSocket Hijacking vulnerability due to missing validation …
2023-01-01Pre-auth
EPSS0.3%
pct 19
5.3
CVE-2024-51775ANC
Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin.
The attacker could a…
2024-01-01Pre-auth
EPSS0.2%
pct 15
6.5
CVE-2026-22689ANC
Mailpit is an email testing tool and API for developers. Prior to version 1.28.2, the Mailpit W…
2026-01-01Pre-auth
EPSS0.2%
pct 10
4.3
CVE-2023-2886CVE
Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing V…
2023-01-01Pre-auth
EPSS0.2%
pct 10
6.5
CVE-2025-56647
npm @farmfe/core before 1.7.6 is Missing Origin Validation in WebSocket. The development (hot m…
2025-01-01Pre-auth
EPSS0.2%
pct 8
7.4
CVE-2025-54289DEB
Privilege Escalation in operations API in Canonical LXD 6.5 on multiple platforms allows attack…
2025-01-01
EPSS0.2%
pct 8
5.5
CVE-2026-34403ANC
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocke…
2026-01-01Pre-auth
EPSS0.2%
pct 7
5.8
CVE-2023-32264
CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulne…
2023-01-01
EPSS0.2%
pct 6
2.3
CVE-2026-27977CVE
Next.js is a React framework for building full-stack web applications. Starting in version 16.0…
2026-01-01Pre-auth
EPSS0.2%
pct 6
6.5
CVE-2026-44514
Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard…
2026-01-01Pre-auth
EPSS0.2%
pct 6
2.3
CVE-2025-48068ANC
Next.js is a React framework for building full-stack web applications. In versions starting fro…
2025-01-01Pre-auth
EPSS0.2%
pct 6
9.3
CVE-2026-35589ANC
nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hija…
2026-01-01Pre-auth
EPSS0.2%
pct 5
4.5
CVE-2026-21883DEB
Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, i…
2026-01-01Pre-auth
EPSS0.2%
pct 5
6.3
CVE-2025-36116CVE
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulner…
2025-01-01
EPSS0.1%
pct 4
6.9
CVE-2025-61987ANC
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and GroupS…
2025-01-01Pre-auth
EPSS0.1%
pct 3
5.4
CVE-2024-8201
Cross-Site WebSocket Hijacking vulnerability in Hitachi Ops Center Analyzer (RAID Agent compone…
2024-01-01Pre-auth
EPSS0.1%
pct 2
5.3
CVE-2026-1692CVE
A missing origin validation in WebSockets vulnerability affects the GraphicalData web services …
2026-01-01Pre-auth
EPSS0.1%
pct 1
Select a vulnerability on the left to open the preview.