Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Parse Server's GraphQL WebSocket endpoint bypasses security middleware | Medium Risk 6.0 | 6 months ago | 3 days ago |
|
|
Incorrect version tags linked to external repository | Critical 9.5 | 5 years ago | 3 days ago |
|
|
ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability | Critical 9.8 | 2 years ago | 18 days ago |
|
|
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection | Critical 10.0 | 2 years ago | 18 days ago |
|
|
Server crashes on invalid Cloud Function or Cloud Job name | Critical 9.0 | 2 years ago | 18 days ago |
|
|
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution | Critical 9.8 | 3 years ago | 18 days ago |
|
|
Invalid push request payload crashes Parse Server | Medium Risk 4.9 | 3 years ago | 18 days ago |
|
|
Parse Server may crash when uploading file without extension | High Risk 7.5 | 2 years ago | 18 days ago |
|
|
Parse Server option `masterKeyIps` vulnerability to IP spoofing | High Risk 8.7 | 3 years ago | 18 days ago |
|
|
Parse Server crashes with query parameter | High Risk 7.5 | 5 years ago | 18 days ago |
|
|
Parse Server stores password in plain text | High Risk 7.7 | 5 years ago | 18 days ago |
|
|
Parse Server before v3.4.1 vulnerable to Denial of Service | High Risk 7.5 | 7 years ago | 18 days ago |
|
|
Sensitive Data Exposure in parse-server | Medium Risk 5.3 | 7 years ago | 18 days ago |
|
|
parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change | Low Risk 3.0 | 3 months ago | 2 months ago |
|
|
parse-server: Stored XSS via non-standard file extension bypassing file upload extension blocklist | Low Risk 3.0 | 3 months ago | 2 months ago |
|
|
parse-server: Denial of service via exponential-time processing of deeply nested query operators | High Risk 8.0 | 3 months ago | 2 months ago |
|
|
parse-server new anonymous user session acts as if it's created with password | Medium Risk 4.8 | 5 years ago | 2 months ago |
|
|
receiving subscription objects with deleted session | Medium Risk 4.3 | 5 years ago | 2 months ago |
|
|
LiveQuery publishes user session tokens in parse-server | High Risk 7.5 | 4 years ago | 2 months ago |
|
|
Information disclosure in parse-server | High Risk 7.7 | 6 years ago | 2 months ago |
|
|
GraphQL: Security breach on Viewer query | Medium Risk 6.5 | 6 years ago | 2 months ago |
|
|
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist | Low Risk 3.0 | 3 months ago | 3 months ago |
|
|
parse-server: Server option routeAllowList is bypassable through batch sub-requests | Medium Risk 6.0 | 3 months ago | 3 months ago |
|
|
parse-server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied | Medium Risk 6.0 | 3 months ago | 3 months ago |
|
|
parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL | Medium Risk 6.0 | 3 months ago | 3 months ago |
|
|
Parse Server: Pre-authentication denial of service via client version header regex backtracking | High Risk 8.0 | 4 months ago | 3 months ago |
|
|
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers | Medium Risk 6.0 | 4 months ago | 3 months ago |
|
|
parse-server: MFA SMS one-time password accepted twice under concurrent login | Low Risk 3.0 | 4 months ago | 4 months ago |
|
|
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields` | Medium Risk 4.3 | 5 months ago | 5 months ago |
|
|
Parse Server has a login timing side-channel reveals user existence | Low Risk 3.7 | 5 months ago | 5 months ago |
|
|
Parse Server: File upload Content-Type override via extension mismatch | Low Risk 3.0 | 5 months ago | 5 months ago |
|
|
Parser Server's streaming file download bypasses afterFind file trigger authorization | High Risk 8.0 | 5 months ago | 5 months ago |
|
|
LiveQuery protected field leak via shared mutable state across concurrent subscribers | High Risk 8.0 | 6 months ago | 5 months ago |
|
|
Parse Server has a session field immutability bypass via falsy-value guard | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
parse-server has cloud function validator bypass via prototype chain traversal | Critical 9.5 | 6 months ago | 5 months ago |
|
|
GraphQL API endpoint ignores CORS origin restriction | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Parse Server exposes auth data via verify password endpoint | High Risk 8.0 | 6 months ago | 5 months ago |
|
|
parse-server has GraphQL complexity validator exponential fragment traversal DoS | High Risk 8.0 | 6 months ago | 5 months ago |
|
|
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value | Medium Risk 6.0 | 6 months ago | 5 months ago |
|
|
Parse Server has an MFA single-use token bypass via concurrent authData login requests | Low Risk 3.0 | 6 months ago | 5 months ago |
|
|
Parse Server has a protected field change detection oracle via LiveQuery watch parameter | Medium Risk 5.3 | 6 months ago | 6 months ago |
|
|
Parse Server has an auth provider validation bypass on login via partial authData | Critical 9.1 | 6 months ago | 6 months ago |
|
|
Parse Server's Session Update endpoint allows overwriting server-generated session fields | Medium Risk 4.3 | 6 months ago | 6 months ago |
|
|
Parse Server email verification resend page leaks user existence | Medium Risk 5.3 | 6 months ago | 6 months ago |
|
|
Parse Server LiveQuery subscription query depth bypass | High Risk 7.5 | 6 months ago | 6 months ago |
|
|
Parse Server has a query condition depth bypass via pre-validation transform pipeline | High Risk 7.5 | 6 months ago | 6 months ago |
|
|
Parse Server's LiveQuery bypasses CLP pointer permission enforcement | Medium Risk 6.5 | 6 months ago | 6 months ago |
|
|
Parse Server exposes auth data via /users/me endpoint | High Risk 8.0 | 6 months ago | 6 months ago |
|
|
Parse Server: MFA recovery code single-use bypass via concurrent requests | Low Risk 3.0 | 6 months ago | 6 months ago |
|
|
Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter | High Risk 8.0 | 6 months ago | 6 months ago |
Page 1