Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 110 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2025-30168 Parse Server has an OAuth login vulnerability parse-communityparse-server Medium 6.9 2025-03-21 14:54:22 Deep Dive
CVE-2024-47183 Parse Server's custom object ID allows to acquire role privileges parse-communityparse-server High 8.1 2024-10-04 15:06:45 Deep Dive
CVE-2024-39309 ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability parse-communityparse-server Critical 9.8 2024-07-01 21:15:26 Deep Dive
CVE-2024-29027 Parse Server crash and RCE via invalid Cloud Function or Cloud Job name parse-communityparse-server Critical 9.0 2024-03-19 18:57:25 Deep Dive
CVE-2024-27298 Parse Server literalizeRegexPart SQL Injection parse-communityparse-server Critical 10.0 2024-03-01 17:48:53 Deep Dive
CVE-2023-46119 Parse Server may crash when uploading file without extension parse-communityparse-server High 7.5 2023-10-25 00:03:56 Deep Dive
CVE-2023-41058 Trigger `beforeFind` not invoked in internal query pipeline in parse-server parse-communityparse-server High 7.5 2023-09-04 22:39:55 Deep Dive
CVE-2023-36475 Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution parse-communityparse-server Critical 9.8 2023-06-28 22:32:10 Deep Dive
CVE-2023-32689 Parse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML file parse-communityparse-server Medium 6.3 2023-05-30 17:27:18 Deep Dive
CVE-2023-32688 Invalid push request payload crashes Parse Server parse-communityparse-server-push-adapter Medium 4.9 2023-05-27 03:21:27 Deep Dive
CVE-2023-22474 Parse Server is vulnerable to authentication bypass via spoofing parse-communityparse-server High 8.7 2023-02-03 19:57:09 Deep Dive
CVE-2022-39396 Parse Server vulnerable to Remote Code Execution via prototype pollution in MongoDB BSON parser parse-communityparse-server Critical 9.8 2022-11-10 00:00:00 Deep Dive
CVE-2022-41878 Parse Server Prototype pollution and Injection via Cloud Code Webhooks or Cloud Code Triggers parse-communityparse-server High 7.2 2022-11-10 00:00:00 Deep Dive
CVE-2022-41879 Parse Server subject to Prototype pollution via Cloud Code Webhooks parse-communityparse-server High 7.2 2022-11-10 00:00:00 Deep Dive
CVE-2022-39313 Parse Server crashes when receiving file download request with invalid byte range parse-communityparse-server High 7.5 2022-10-24 00:00:00 Deep Dive
CVE-2022-39231 Parse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumvented parse-communityparse-server Low 3.7 2022-09-23 07:40:08 Deep Dive
CVE-2022-39225 Parse Server subject to Incorrect Resource Transfer Between Spheres parse-communityparse-server Medium 4.3 2022-09-23 06:40:07 Deep Dive
CVE-2022-36079 Parse Server vulnerable to brute force guessing of user sensitive data via search patterns parse-communityparse-server High 8.6 2022-09-07 20:40:13 Deep Dive
CVE-2022-31112 Protected fields exposed via LiveQuery in parse-server parse-communityparse-server High 8.2 2022-06-30 16:40:13 Deep Dive
CVE-2022-31089 Invalid file request can crashe parse-server parse-communityparse-server High 7.5 2022-06-27 21:10:11 Deep Dive