Parse-Server

Parseplatform · 102 CVEs

CVE-2024-29027
CRITICAL

Parse Server crash and RCE via invalid Cloud Function or Cloud Job name

Mar 19, 2024

CVE-2024-27298
CRITICAL

Parse Server literalizeRegexPart SQL Injection

Mar 1, 2024

CVE-2023-46119
HIGH

Parse Server may crash when uploading file without extension

Oct 25, 2023

CVE-2023-41058
HIGH

Trigger `beforeFind` not invoked in internal query pipeline in parse-server

Sep 4, 2023

CVE-2023-36475
CRITICAL

Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution

Jun 28, 2023

CVE-2023-32689
MEDIUM

Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file

May 30, 2023

CVE-2023-22474
HIGH

Parse Server is vulnerable to authentication bypass via spoofing

Feb 3, 2023

CVE-2022-41879
CRITICAL

Parse Server subject to Prototype pollution via Cloud Code Webhooks

Nov 10, 2022

CVE-2022-41878
CRITICAL

Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers

Nov 10, 2022

CVE-2022-39396
CRITICAL

Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser

Nov 10, 2022

CVE-2022-39313
HIGH

Parse Server crashes when receiving file download request with invalid byte range

Oct 24, 2022

CVE-2022-39231
LOW

Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented

Sep 23, 2022

CVE-2022-39225
MEDIUM

Parse Server subject to Incorrect Resource Transfer Between Spheres

Sep 23, 2022

CVE-2022-36079
HIGH

Parse Server vulnerable to brute force guessing of user sensitive data via search patterns

Sep 7, 2022

CVE-2022-31112
HIGH

Protected fields exposed via LiveQuery in parse-server

Jun 30, 2022

CVE-2022-31089
HIGH

Invalid file request can crashe parse-server

Jun 27, 2022

CVE-2022-31083
HIGH

Authentication bypass in Parse Server Apple Game Center auth adapter

Jun 17, 2022

CVE-2022-24901
HIGH

Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter

May 4, 2022

CVE-2022-24760
CRITICAL

Command Injection in Parse server

Mar 11, 2022

CVE-2021-41109
HIGH

LiveQuery publishes user session tokens

Sep 30, 2021

CVE-2021-39187
HIGH

Crash server with query parameter

Sep 2, 2021

CVE-2021-39138
MEDIUM

New anonymous user session acts as if it's created with password

Aug 18, 2021

CVE-2020-26288
LOW

Parse Server stores password in plain text

Dec 30, 2020

CVE-2020-15270
MEDIUM

Improper session expiration in Parse Server

Oct 22, 2020

CVE-2020-5251
HIGH

Information disclosure in parse-server

Mar 4, 2020

Showing 76 to 100 of 102 CVEs