CVE-2026-33421
- EPSS 0.01%
- Veröffentlicht 24.03.2026 18:14:30
- Zuletzt bearbeitet 25.03.2026 21:22:58
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.53 and 9.6.0-alpha.42, Parse Server's LiveQuery WebSocket interface does not enforce Class-Level Permission (CLP) pointer pe...
CVE-2026-33409
- EPSS 0.05%
- Veröffentlicht 24.03.2026 18:11:36
- Zuletzt bearbeitet 25.03.2026 21:25:29
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.52 and 9.6.0-alpha.41, an authentication bypass vulnerability allows an attacker to log in as any user who has linked a thir...
CVE-2026-33323
- EPSS 0.04%
- Veröffentlicht 24.03.2026 18:06:32
- Zuletzt bearbeitet 25.03.2026 21:25:47
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.51 and 9.6.0-alpha.40, the Pages route and legacy PublicAPI route for resending email verification links return distinguisha...
CVE-2026-33163
- EPSS 0.03%
- Veröffentlicht 18.03.2026 21:58:04
- Zuletzt bearbeitet 19.03.2026 16:35:28
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.35 and 8.6.50, when a `Parse.Cloud.afterLiveQueryEvent` trigger is registered for a class, the LiveQuery server leaks protect...
CVE-2026-33042
- EPSS 0.01%
- Veröffentlicht 18.03.2026 21:54:05
- Zuletzt bearbeitet 19.03.2026 16:44:02
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.29 and 8.6.49, a user can sign up without providing credentials by sending an empty `authData` object, bypassing the username...
CVE-2026-32944
- EPSS 0.02%
- Veröffentlicht 18.03.2026 21:50:08
- Zuletzt bearbeitet 19.03.2026 16:46:28
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.21 and 8.6.45, an unauthenticated attacker can crash the Parse Server process by sending a single request with deeply nested ...
CVE-2026-32943
- EPSS 0.03%
- Veröffentlicht 18.03.2026 21:46:17
- Zuletzt bearbeitet 19.03.2026 16:55:36
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.28 and 8.6.48, the password reset mechanism does not enforce single-use guarantees for reset tokens. When a user requests a p...
CVE-2026-32886
- EPSS 0.03%
- Veröffentlicht 18.03.2026 21:42:27
- Zuletzt bearbeitet 19.03.2026 17:21:45
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.24 and 8.6.47, remote clients can crash the Parse Server process by calling a cloud function endpoint with a crafted function...
CVE-2026-32878
- EPSS 0.01%
- Veröffentlicht 18.03.2026 21:40:34
- Zuletzt bearbeitet 19.03.2026 17:28:32
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.20 and 8.6.44, an attacker can bypass the default request keyword denylist protection and the class-level permission for addi...
CVE-2026-32770
- EPSS 0.04%
- Veröffentlicht 18.03.2026 21:37:36
- Zuletzt bearbeitet 19.03.2026 17:32:00
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.19 and 8.6.43, a remote attacker can crash the Parse Server by subscribing to a LiveQuery with an invalid regular expression ...