CVE-2026-34363
- EPSS 0.04%
- Veröffentlicht 31.03.2026 14:35:42
- Zuletzt bearbeitet 02.04.2026 18:11:29
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.65 and 9.7.0-alpha.9, when multiple clients subscribe to the same class via LiveQuery, the event handlers process each subsc...
CVE-2026-34224
- EPSS 0.04%
- Veröffentlicht 31.03.2026 14:25:22
- Zuletzt bearbeitet 02.04.2026 16:16:23
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.64 and 9.7.0-alpha.8, an attacker who possesses a valid authentication provider token and a single MFA recovery code or SMS ...
CVE-2026-33627
- EPSS 0.06%
- Veröffentlicht 24.03.2026 18:31:14
- Zuletzt bearbeitet 25.03.2026 21:16:08
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.61 and 9.6.0-alpha.55, an authenticated user calling GET /users/me receives unsanitized auth data, including sensitive crede...
CVE-2026-33624
- EPSS 0.03%
- Veröffentlicht 24.03.2026 18:28:52
- Zuletzt bearbeitet 25.03.2026 21:17:05
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code...
CVE-2026-33539
- EPSS 0.06%
- Veröffentlicht 24.03.2026 18:26:56
- Zuletzt bearbeitet 25.03.2026 21:18:00
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL database by...
CVE-2026-33538
- EPSS 0.09%
- Veröffentlicht 24.03.2026 18:24:51
- Zuletzt bearbeitet 25.03.2026 21:18:30
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, an unauthenticated attacker can cause denial of service by sending authentication requests with arbit...
CVE-2026-33527
- EPSS 0.01%
- Veröffentlicht 24.03.2026 18:22:44
- Zuletzt bearbeitet 25.03.2026 21:19:48
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and createdWith...
CVE-2026-33508
- EPSS 0.06%
- Veröffentlicht 24.03.2026 18:21:08
- Zuletzt bearbeitet 25.03.2026 21:21:17
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth configuration se...
CVE-2026-33498
- EPSS 0.06%
- Veröffentlicht 24.03.2026 18:18:44
- Zuletzt bearbeitet 25.03.2026 21:21:45
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply nested query containing logical op...
CVE-2026-33429
- EPSS 0.04%
- Veröffentlicht 24.03.2026 18:16:35
- Zuletzt bearbeitet 25.03.2026 21:22:23
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.54 and 9.6.0-alpha.43, an attacker can subscribe to LiveQuery with a watch parameter targeting a protected field. Although t...