Parse-Server
Parseplatform · 102 CVEs
Parse Server crash and RCE via invalid Cloud Function or Cloud Job name
Mar 19, 2024
Parse Server literalizeRegexPart SQL Injection
Mar 1, 2024
Parse Server may crash when uploading file without extension
Oct 25, 2023
Trigger `beforeFind` not invoked in internal query pipeline in parse-server
Sep 4, 2023
Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
Jun 28, 2023
Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file
May 30, 2023
Parse Server is vulnerable to authentication bypass via spoofing
Feb 3, 2023
Parse Server subject to Prototype pollution via Cloud Code Webhooks
Nov 10, 2022
Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers
Nov 10, 2022
Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser
Nov 10, 2022
Parse Server crashes when receiving file download request with invalid byte range
Oct 24, 2022
Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented
Sep 23, 2022
Parse Server subject to Incorrect Resource Transfer Between Spheres
Sep 23, 2022
Parse Server vulnerable to brute force guessing of user sensitive data via search patterns
Sep 7, 2022
Protected fields exposed via LiveQuery in parse-server
Jun 30, 2022
Invalid file request can crashe parse-server
Jun 27, 2022
Authentication bypass in Parse Server Apple Game Center auth adapter
Jun 17, 2022
Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter
May 4, 2022
Command Injection in Parse server
Mar 11, 2022
LiveQuery publishes user session tokens
Sep 30, 2021
Crash server with query parameter
Sep 2, 2021
New anonymous user session acts as if it's created with password
Aug 18, 2021
Parse Server stores password in plain text
Dec 30, 2020
Improper session expiration in Parse Server
Oct 22, 2020
Information disclosure in parse-server
Mar 4, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-29027 | Parse Server crash and RCE via invalid Cloud Function or Cloud Job name | CRITICAL | 1.19% | Mar 19, 2024 |
| CVE-2024-27298 | Parse Server literalizeRegexPart SQL Injection | CRITICAL | 1.03% | Mar 1, 2024 |
| CVE-2023-46119 | Parse Server may crash when uploading file without extension | HIGH | 1.05% | Oct 25, 2023 |
| CVE-2023-41058 | Trigger `beforeFind` not invoked in internal query pipeline in parse-server | HIGH | 0.77% | Sep 4, 2023 |
| CVE-2023-36475 | Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution | CRITICAL | 3.20% | Jun 28, 2023 |
| CVE-2023-32689 | Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file | MEDIUM | 0.64% | May 30, 2023 |
| CVE-2023-22474 | Parse Server is vulnerable to authentication bypass via spoofing | HIGH | 0.66% | Feb 3, 2023 |
| CVE-2022-41879 | Parse Server subject to Prototype pollution via Cloud Code Webhooks | CRITICAL | 0.86% | Nov 10, 2022 |
| CVE-2022-41878 | Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers | CRITICAL | 0.93% | Nov 10, 2022 |
| CVE-2022-39396 | Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser | CRITICAL | 38.72% | Nov 10, 2022 |
| CVE-2022-39313 | Parse Server crashes when receiving file download request with invalid byte range | HIGH | 0.75% | Oct 24, 2022 |
| CVE-2022-39231 | Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented | LOW | 0.51% | Sep 23, 2022 |
| CVE-2022-39225 | Parse Server subject to Incorrect Resource Transfer Between Spheres | MEDIUM | 0.48% | Sep 23, 2022 |
| CVE-2022-36079 | Parse Server vulnerable to brute force guessing of user sensitive data via search patterns | HIGH | 1.26% | Sep 7, 2022 |
| CVE-2022-31112 | Protected fields exposed via LiveQuery in parse-server | HIGH | 1.30% | Jun 30, 2022 |
| CVE-2022-31089 | Invalid file request can crashe parse-server | HIGH | 1.13% | Jun 27, 2022 |
| CVE-2022-31083 | Authentication bypass in Parse Server Apple Game Center auth adapter | HIGH | 0.87% | Jun 17, 2022 |
| CVE-2022-24901 | Authentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter | HIGH | 0.69% | May 4, 2022 |
| CVE-2022-24760 | Command Injection in Parse server | CRITICAL | 49.08% | Mar 11, 2022 |
| CVE-2021-41109 | LiveQuery publishes user session tokens | HIGH | 1.25% | Sep 30, 2021 |
| CVE-2021-39187 | Crash server with query parameter | HIGH | 1.82% | Sep 2, 2021 |
| CVE-2021-39138 | New anonymous user session acts as if it's created with password | MEDIUM | 0.99% | Aug 18, 2021 |
| CVE-2020-26288 | Parse Server stores password in plain text | LOW | 0.81% | Dec 30, 2020 |
| CVE-2020-15270 | Improper session expiration in Parse Server | MEDIUM | 1.17% | Oct 22, 2020 |
| CVE-2020-5251 | Information disclosure in parse-server | HIGH | 0.85% | Mar 4, 2020 |
Showing 76 to 100 of 102 CVEs