Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2604▼ 298 respecto a la semana anterior
Críticas / altas1314▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)76▼ 451 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.68% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker can crash the Parse Server process by calling a Cloud Function endpoint with a prototype property name as the function name. The server recurses… | |
| Analizada | Media (6.9) | 0.41% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 and 9.5.1-alpha.1, the requestKeywordDenylist security control can be bypassed by placing any nested object or array before a prohibited keyword in the request payload. This is caused by a logic bug… | |
| Analizada | Alta (8.2) | 0.61% | — | Parseplatform Parse-server | 10/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js event loop. This makes the entire Parse… | |
| Analizada | Crítica (9.3) | 0.71% | — | Parseplatform Parse-server | 7/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.10 and 9.5.0-alpha.11, the Google, Apple, and Facebook authentication adapters use JWT verification to validate identity tokens. When the adapter's audience configuration option is not set… | |
| Analizada | Media (6.9) | 0.35% | — | Parseplatform Parse-server | 7/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.3.1-alpha.3 to before version 9.5.0-alpha.10, when graphQLPublicIntrospection is disabled, __type queries nested inside inline fragments (e.g. ... on Query { __type(name:"User") { name } }) bypass the… | |
| Analizada | Media (6.3) | 0.35% | — | Parseplatform Parse-server | 7/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.9 and 9.5.0-alpha.9, the file metadata endpoint (GET /files/:appId/metadata/:filename) does not enforce beforeFind / afterFind file triggers. When these triggers are used as access-control… | |
| Analizada | Media (6.3) | 0.35% | — | Parseplatform Parse-server | 7/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.8 and 9.5.0-alpha.8, the PagesRouter static file serving route is vulnerable to a path traversal attack that allows unauthenticated reading of files outside the configured pagesPath directory.… | |
| Analizada | Media (6.9) | 0.42% | — | Parseplatform Parse-server | 6/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.7 and 9.5.0-alpha.6, malformed $regex query parameter (e.g. [abc) causes the database to return a structured error object that is passed unsanitized through the API response. This leaks… | |
| Analizada | Alta (8.5) | 0.58% | — | Parseplatform Parse-server | 6/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.6 and 9.5.0-alpha.4, the readOnlyMasterKey can call POST /loginAs to obtain a valid session token for any user. This allows a read-only credential to impersonate arbitrary users with full read… | |
| Analizada | Media (6.9) | 0.45% | — | Parseplatform Parse-server | 6/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.5 and 9.5.0-alpha.3, the readOnlyMasterKey can be used to create and delete files via the Files API (POST /files/:filename, DELETE /files/:filename). This bypasses the read-only restriction… | |
| Analizada | Alta (8.6) | 0.58% | — | Parseplatform Parse-server | 6/3/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.4 and 9.4.1-alpha.3, Parse Server's readOnlyMasterKey option allows access with master-level read privileges but is documented to deny all write operations. However, some endpoints incorrectly… | |
| Analizada | Crítica (9.3) | 0.23% | — | Parseplatform Parse-server | 26/2/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.3 and 9.1.1-alpha.4, an unauthenticated attacker can forge a Google authentication token with `alg: "none"` to log in as any user linked to a Google account, without knowing their credentials.… | |
| Analizada | Alta (8.3) | 0.33% | — | Parseplatform Parse-server | 16/12/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, the Instagram authentication adapter allows clients to specify a custom API URL via the `apiURL` parameter in `authData`. This enables SSRF attacks and possibly… | |
| Analizada | Media (5.3) | 0.22% | — | Parseplatform Parse-server | 16/12/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Parse Server's password reset and email verification HTML pages. The patch, available in versions 8.6.1… | |
| Analizada | Media (6.9) | 0.42% | — | Parseplatform Parse-server | 12/12/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI workflow is triggered in a way that grants the GitHub Actions workflow elevated permissions, giving it access to GitHub secrets and write permissions which are defined in… | |
| Aplazada | Media (6.9) | 0.42% | — | MongodbAIParseplatform Parse ServerAI | 10/11/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `explain()` method provides detailed information about query execution plans, including index usage, collection scanning behavior, and performance metrics. Prior to version 8.5.0-alpha.5, Parse Server… | |
| Aplazada | Alta (7.5) | 0.60% | — | Parseplatform Parse ServerAI | 7/11/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.0 through 7.5.3, and 8.0.0 through 8.3.1-alpha.1, there is a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality when trying to upload a Parse.File with uri parameter,… | |
| Aplazada | Media (5.3) | 0.94% | — | Parseplatform Parse ServerAI | 10/7/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. While schema introspection… | |
| Aplazada | Media (6.9) | 0.40% | — | Parseplatform Parse ServerAI | 21/3/2025 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 7.5.2 and 8.0.2, the 3rd party authentication handling of Parse Server allows the authentication credentials of some specific authentication providers to be used across multiple Parse Server apps. For… | |
| Analizada | Alta (8.1) | 0.42% | — | Parseplatform Parse-server | 4/10/2024 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true is set, an attacker that is allowed to create a new user can set a custom object ID for that new user that exploits the vulnerability and acquires privileges of a… | |
| Aplazada | Crítica (9.8) | 20% | — | PostgresqlAIParseplatform Parse ServerAI | 1/7/2024 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and… | |
| Analizada | Crítica (9) | 1.2% | — | Parseplatform Parse-server | 19/3/2024 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling an invalid Parse Server Cloud Function name or Cloud Job name crashes the server and may allow for code injection, internal store manipulation or remote code… | |
| Analizada | Crítica (10) | 1.0% | — | Parseplatform Parse-server | 1/3/2024 | 17/6/2026 | parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20. | |
| Modificada | Alta (7.5) | 1.1% | — | Parseplatform Parse-server | 25/10/2023 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1. | |
| Modificada | Alta (7.5) | 0.77% | — | Parseplatform Parse-server | 4/9/2023 | 17/6/2026 | Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked in certain conditions of `Parse.Query`. This can pose a vulnerability for deployments where the `beforeFind` trigger is used as a security layer to modify the incoming query. The vulnerability has… |