CVE-2026-30965
- EPSS 0.08%
- Veröffentlicht 10.03.2026 20:43:52
- Zuletzt bearbeitet 11.03.2026 15:31:39
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltr...
CVE-2026-30962
- EPSS 0.04%
- Veröffentlicht 10.03.2026 20:42:22
- Zuletzt bearbeitet 11.03.2026 16:59:34
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the validation for protected fields only checks top-level query keys. By wrapping a query constraint on a prote...
CVE-2026-30949
- EPSS 0.04%
- Veröffentlicht 10.03.2026 20:20:12
- Zuletzt bearbeitet 11.03.2026 19:40:59
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak access token...
CVE-2026-30948
- EPSS 0.02%
- Veröffentlicht 10.03.2026 20:18:23
- Zuletzt bearbeitet 11.03.2026 17:14:26
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored cross-site scripting (XSS) vulnerability allows any authenticated user to upload an SVG file containin...
CVE-2026-30947
- EPSS 0.02%
- Veröffentlicht 10.03.2026 20:16:34
- Zuletzt bearbeitet 11.03.2026 17:15:05
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-level permissions (CLP) are not enforced for LiveQuery subscriptions. An unauthenticated or unauthorized ...
CVE-2026-30946
- EPSS 0.02%
- Veröffentlicht 10.03.2026 20:14:48
- Zuletzt bearbeitet 11.03.2026 17:16:26
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) through crafted...
CVE-2026-30941
- EPSS 0.06%
- Veröffentlicht 10.03.2026 16:40:13
- Zuletzt bearbeitet 11.03.2026 19:42:29
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the toke...
CVE-2026-30939
- EPSS 0.17%
- Veröffentlicht 10.03.2026 16:37:50
- Zuletzt bearbeitet 11.03.2026 19:51:33
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker can crash the Parse Server process by calling a Cloud Function endpoint with a prot...
CVE-2026-30938
- EPSS 0.06%
- Veröffentlicht 10.03.2026 16:34:02
- Zuletzt bearbeitet 11.03.2026 19:53:02
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 and 9.5.1-alpha.1, the requestKeywordDenylist security control can be bypassed by placing any nested object or array before a proh...
CVE-2026-30925
- EPSS 0.02%
- Veröffentlicht 09.03.2026 23:01:32
- Zuletzt bearbeitet 11.03.2026 19:53:57
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtra...