Vulnerabilities
Summary — last 7 days
New vulnerabilities2,770▲ 14 vs. last week
Critical / high1,475▲ 292 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)68▼ 447 vs. last week
125 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.4) | 0.21% | — | Parseplatform Parse ServerAI | 9/27/2026 | 9/30/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup… | |
| Awaiting Analysis | High (7.1) | 0.29% | — | Parseplatform Parse ServerAI | 9/26/2026 | 9/30/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own… | |
| Awaiting Analysis | High (8.7) | 0.36% | — | Parseplatform Parse ServerAI | 9/26/2026 | 9/30/2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated… | |
| Deferred | Medium (6.3) | 0.45% | — | Parseplatform Parse ServerAI | 7/24/2026 | 7/30/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom input fields even when public introspection is disabled (graphQLPublicIntrospection: false, the default). A client holding only the public application id — with no user… | |
| Deferred | Medium (6.3) | 0.56% | — | Parseplatform Parse ServerAI | 7/24/2026 | 7/27/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL validation and input-coercion error messages when public schema introspection is disabled (graphQLPublicIntrospection: false, the default). Because these errors are produced… | |
| Deferred | Medium (6.9) | 0.47% | — | Parseplatform Parse ServerAI | 7/21/2026 | 7/23/2026 | Parse Server versions >= 9.0.0 before 9.10.0-alpha.4 and versions before 8.6.85 contain a schema disclosure vulnerability. When the GraphQL API is mounted with public introspection disabled (graphQLPublicIntrospection: false, the default), schema-derived 'Did you mean ...?' suggestions were still returned in GraphQL… | |
| Deferred | Low (2.1) | 0.41% | — | Parseplatform Parse ServerAI | 7/11/2026 | 7/13/2026 | Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension is not recognized by the mime package, Parse Server preserves the client-supplied Content-Type. A malformed Content-Type that is not a valid type/subtype… | |
| Deferred | Low (2.3) | 0.53% | — | Parseplatform Parse ServerAI | 7/8/2026 | 7/10/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.13 and 8.6.83, a LiveQuery subscriber could receive object field values they were not authorized to read when a single save changed both an object field and the subscriber's ACL read access,… | |
| Deferred | High (8.7) | 0.59% | — | Parseplatform Parse ServerAI | 7/8/2026 | 7/10/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82, deeply nested $or, $and, and $nor query condition operators in the REST API or LiveQuery query handling could trigger exponential-time processing in the internal query-traversal… | |
| Deferred | High (7.7) | 0.18% | — | Parseplatform Parse ServerAI | 6/25/2026 | 6/26/2026 | Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based… | |
| Analyzed | High (7.7) | 0.18% | — | Parseplatform Parse-server | 6/25/2026 | 7/30/2026 | Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code. | |
| Deferred | Medium (6.9) | 0.48% | — | Parseplatform Parse ServerAI | 6/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator could read the membership of a Relation field even when that field was hidden from the requesting client by protectedFields,… | |
| Deferred | Medium (5.9) | 0.43% | — | Parseplatform Parse ServerAI | 6/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _User class via Class-Level Permissions could expose sensitive user data through the /login and /verifyPassword endpoints.… | |
| Deferred | Low (2.1) | 0.49% | — | Parseplatform Parse ServerAI | 6/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be bypassed by appending a trailing dot to a filename whose extension would otherwise be blocked (e.g. poc.svg.). The… | |
| Deferred | Medium (6.9) | 0.60% | — | Parseplatform Parse ServerAI | 6/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts external client access to a configured list of REST API routes. The check is only enforced as Express middleware against… | |
| Deferred | Medium (6.9) | 0.51% | — | Parseplatform Parse ServerAI | 6/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.78 and 9.9.1-alpha.2, Parse Server's GraphQL endpoint discloses schema metadata to unauthenticated callers through Did you mean ...? suggestions embedded in GraphQL validation-error messages.… | |
| Deferred | High (8.7) | 0.91% | — | Parseplatform Parse ServerAI | 6/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-known Parse Application ID can submit a single HTTP request whose client SDK version field contains adversarial input that… | |
| Analyzed | Low (2.1) | 0.30% | — | Parseplatform Parse-server | 5/12/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) login path allows two concurrent /login requests carrying the same OTP to both succeed and both receive valid session… | |
| Analyzed | Medium (5.3) | 0.32% | — | Parseplatform Parse-server | 4/7/2026 | 7/24/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.7 and 8.6.75, the GET /sessions/me endpoint returns _Session fields that the server operator explicitly configured as protected via the protectedFields server option. Any authenticated user can… | |
| Analyzed | Medium (6.3) | 0.37% | — | Parseplatform Parse-server | 4/7/2026 | 6/17/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-alpha.6 and 8.6.74, he login endpoint response time differs measurably depending on whether the submitted username or email exists in the database. When a user is not found, the server responds… | |
| Analyzed | Low (2.1) | 0.28% | — | Parseplatform Parse-server | 4/6/2026 | 7/24/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 and 9.7.1-alpha.4, a file can be uploaded with a filename extension that passes the file extension allowlist (e.g., .txt) but with a Content-Type header that differs from the extension (e.g.,… | |
| Analyzed | High (8.2) | 0.47% | — | Parseplatform Parse-server | 3/31/2026 | 7/24/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.71 and 9.7.1-alpha.1, file downloads via HTTP Range requests bypass the afterFind(Parse.File) trigger and its validators on storage adapters that support streaming (e.g. the default GridFS… | |
| Modified | High (8.2) | 0.53% | — | Parseplatform Parse-server | 3/31/2026 | 7/24/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.63 and 9.7.0-alpha.7, the verify password endpoint returns unsanitized authentication data, including MFA TOTP secrets, recovery codes, and OAuth access tokens. An attacker who knows a user's… | |
| Analyzed | Medium (5.3) | 0.43% | — | Parseplatform Parse-server | 3/31/2026 | 7/24/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.70 and 9.7.0-alpha.18, an authenticated user with find class-level permission can bypass the protectedFields class-level permission setting on LiveQuery subscriptions. By sending a subscription… | |
| Analyzed | Medium (5.3) | 0.34% | — | Parseplatform Parse-server | 3/31/2026 | 7/24/2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.69 and 9.7.0-alpha.14, an authenticated user can bypass the immutability guard on session fields (expiresAt, createdWith) by sending a null value in a PUT request to the session update… |