Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
125 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.21% | — | Parseplatform Parse ServerAI | 27/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own… | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated… | |
| Aplazada | Media (6.3) | 0.45% | — | Parseplatform Parse ServerAI | 24/7/2026 | 30/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user… | |
| Aplazada | Media (6.3) | 0.56% | — | Parseplatform Parse ServerAI | 24/7/2026 | 27/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the default). Because these errors are produced… | |
| Aplazada | Media (6.9) | 0.47% | — | Parseplatform Parse ServerAI | 21/7/2026 | 23/7/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL… | |
| Aplazada | Baja (2.1) | 0.41% | — | Parseplatform Parse ServerAI | 11/7/2026 | 13/7/2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed Content-Type that is not a valid type/subtype… | |
| Aplazada | Baja (2.3) | 0.53% | — | Parseplatform Parse ServerAI | 8/7/2026 | 10/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access,… | |
| Aplazada | Alta (8.7) | 0.59% | — | Parseplatform Parse ServerAI | 8/7/2026 | 10/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time processing in the internal query-traversal… | |
| Aplazada | Alta (7.7) | 0.18% | — | Parseplatform Parse ServerAI | 25/6/2026 | 26/6/2026 | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based… | |
| Analizada | Alta (7.7) | 0.18% | — | Parseplatform Parse-server | 25/6/2026 | 30/7/2026 | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code. | |
| Aplazada | Media (6.9) | 0.48% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from the requesting client by protectedFields,… | |
| Aplazada | Media (5.9) | 0.43% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions could expose sensitive user data through the /login and /verifyPassword endpoints.… | |
| Aplazada | Baja (2.1) | 0.49% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. poc.svg.). The… | |
| Aplazada | Media (6.9) | 0.60% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is only enforced as Express middleware against… | |
| Aplazada | Media (6.9) | 0.51% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded in GraphQL validation-error messages.… | |
| Aplazada | Alta (8.7) | 0.91% | — | Parseplatform Parse ServerAI | 12/6/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that… | |
| Analizada | Baja (2.1) | 0.30% | — | Parseplatform Parse-server | 12/5/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succeed and both receive valid session… | |
| Analizada | Media (5.3) | 0.32% | — | Parseplatform Parse-server | 7/4/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protected via the protectedFields server option. Any authenticated user can… | |
| Analizada | Media (6.3) | 0.37% | — | Parseplatform Parse-server | 7/4/2026 | 17/6/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds… | |
| Analizada | Baja (2.1) | 0.28% | — | Parseplatform Parse-server | 6/4/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the extension (e.g.,… | |
| Analizada | Alta (8.2) | 0.47% | — | Parseplatform Parse-server | 31/3/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the default GridFS… | |
| Modificada | Alta (8.2) | 0.53% | — | Parseplatform Parse-server | 31/3/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, recovery codes, and OAuth access tokens. An attacker who knows a user's… | |
| Analizada | Media (5.3) | 0.43% | — | Parseplatform Parse-server | 31/3/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions. By sending a subscription… | |
| Analizada | Media (5.3) | 0.34% | — | Parseplatform Parse-server | 31/3/2026 | 24/7/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update… |