Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.47% | — | Parseplatform Parse-server | 16/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 and 9.6.0-alpha.14, the GraphQL WebSocket endpoint for subscriptions does not pass requests through the Express middleware chain that enforces authentication, introspection control, and query… | |
| Analizada | Media (6.3) | 0.40% | — | Parseplatform Parse-server | 12/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly validate app IDs when appidField and appIds are configured. During app ID validation, a malformed value is sent to the token… | |
| Analizada | Crítica (9.3) | 0.92% | — | Parseplatform Parse-server | 12/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identifier (e.g.… | |
| Analizada | Crítica (9.1) | 0.38% | — | Parseplatform Parse-server | 12/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singleton instance that is reused directly across all OAuth2 provider configurations. Under concurrent authentication… | |
| Analizada | Media (5.1) | 0.33% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.10 and 8.6.36, an attacker with access to the master key can inject malicious SQL via crafted field names used in query constraints when Parse Server is configured with PostgreSQL as the… | |
| Analizada | Media (6.9) | 0.49% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.9 and 8.6.35, an attacker can exploit LiveQuery subscriptions to infer the values of protected fields without directly receiving them. By subscribing with a WHERE clause that references a… | |
| Analizada | Media (6.3) | 0.40% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 and 9.6.0-alpha.8, the email verification endpoint (/verificationEmailRequest) returns distinct error responses depending on whether an email address belongs to an existing user, is already verified,… | |
| Analizada | Alta (8.2) | 0.52% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These codes are intended as a fallback when the… | |
| Analizada | Alta (8.7) | 0.47% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and sort parameters. An attacker can use dot-notation to query or sort by… | |
| Analizada | Crítica (9.3) | 0.54% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.5 and 8.6.31, a SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The… | |
| Analizada | Media (6.3) | 0.33% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.4 and 8.6.30, an attacker can upload a file with a file extension or content type that is not blocked by the default configuration of the Parse Server fileUpload.fileExtensions option. The file… | |
| Analizada | Crítica (9.3) | 0.54% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The amount value is interpolated directly… | |
| Analizada | Crítica (9.3) | 0.70% | — | Parseplatform Parse-server | 11/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.2 and 8.6.28, an attacker can use a dot-notation field name in combination with the sort query parameter to inject SQL into the PostgreSQL database through an improper escaping of sub-field… | |
| Analizada | Media (6) | 0.76% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.13 and 8.6.26, the LDAP authentication adapter is vulnerable to LDAP injection. User-supplied input (authData.id) is interpolated directly into LDAP Distinguished Names (DN) and group search… | |
| Analizada | Alta (8.8) | 0.59% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.12 and 8.6.25, the _GraphQLConfig and _Audience internal classes can be read, modified, and deleted via the generic /classes/_GraphQLConfig and /classes/_Audience REST API routes without master… | |
| Analizada | Media (6.9) | 0.61% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior o 9.5.2-alpha.10 and 8.6.23, Parse Server's rate limiting middleware is applied at the Express middleware layer, but the batch request endpoint (/batch) processes sub-requests internally by routing them… | |
| Analizada | Alta (7.6) | 0.64% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.9. and 8.6.22, the OAuth2 authentication adapter, when configured without the useridField option, only verifies that a token is active via the provider's token introspection endpoint, but does… | |
| Analizada | Crítica (10) | 0.52% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.7 and 8.6.20, Parse Server's internal tables, which store Relation field mappings such as role memberships, can be directly accessed via the REST API or GraphQL API by any client using only the… | |
| Analizada | Crítica (9.9) | 1.6% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.8 and 8.6.21, a vulnerability in Parse Server's query handling allows an authenticated or unauthenticated attacker to exfiltrate session tokens of other users by exploiting the… | |
| Analizada | Alta (7.1) | 0.40% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.6 and 8.6.19, the validation for protected fields only checks top-level query keys. By wrapping a query constraint on a protected field inside a logical operator, the check is bypassed entirely.… | |
| Analizada | Alta (7.6) | 0.64% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.5 and 8.6.18, the Keycloak authentication adapter does not validate the azp (authorized party) claim of Keycloak access tokens against the configured client-id. A valid access token issued by… | |
| Analizada | Alta (8.3) | 0.29% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.4 and 8.6.17, a stored cross-site scripting (XSS) vulnerability allows any authenticated user to upload an SVG file containing JavaScript. The file is served inline with Content-Type:… | |
| Analizada | Alta (8.7) | 0.47% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-alpha.3 and 8.6.16, class-level permissions (CLP) are not enforced for LiveQuery subscriptions. An unauthenticated or unauthorized client can subscribe to any LiveQuery-enabled class and receive… | |
| Analizada | Alta (8.7) | 0.64% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior 9.5.2-alpha.2 and 8.6.15, an unauthenticated attacker can exhaust Parse Server resources (CPU, memory, database connections) through crafted queries that exploit the lack of complexity limits in the REST and… | |
| Analizada | Alta (8.7) | 0.47% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the token field in the password reset and email verification resend… |