Where
-Infinity
0

parseplatform Parse-server Node.jsParse Server - Unreviewed Code Execution via Malicious Version Tags

Risk 68
Severity
7.7
First published (updated )

parseplatform Parse-server Node.jsParse Server: MFA SMS one-time password accepted twice under concurrent login

Risk 35
Severity
2.1
First published (updated )

parseplatform Parse-server Node.jsParse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`

Risk 26
Severity
5.3
First published (updated )

parseplatform Parse-server Node.jsParse Server has a login timing side-channel reveals user existence

Risk 27
Severity
6.3
First published (updated )

parseplatform Parse-server Node.jsParse Server has a file upload Content-Type override via extension mismatch

Risk 34
Severity
2.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/parse-serverParse Server: Streaming file download bypasses afterFind file trigger authorization

Risk 43
Severity
8.2
First published (updated )

parseplatform Parse-server Node.jsParse Server: LiveQuery protected-field guard bypass via array-like logical operator value

Risk 26
Severity
5.3
First published (updated )

parseplatform Parse-server Node.jsParse Server: Session field immutability bypass via falsy-value guard

Risk 34
Severity
5.3
First published (updated )

parseplatform Parse-server Node.jsParse Server: GraphQL complexity validator exponential fragment traversal DoS

Risk 43
Severity
8.2
First published (updated )

parseplatform Parse-server Node.jsParse Server: Cloud function validator bypass via prototype chain traversal

Risk 63
Severity
9.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server: GraphQL API endpoint ignores CORS origin restriction

Risk 77
Severity
5.3
First published (updated )

parseplatform Parse-server Node.jsParse Server: LiveQuery protected field leak via shared mutable state across concurrent subscribers

Risk 43
Severity
8.2
First published (updated )

parseplatform Parse-server Node.jsParse Server: MFA single-use token bypass via concurrent authData login requests

Risk 26
Severity
2.1
First published (updated )

parseplatform Parse-server Node.jsParse Server: Auth data exposed via verify password endpoint

Risk 40
Severity
8.2
First published (updated )

parseplatform Parse-server Node.jsParse Server: Auth data exposed via /users/me endpoint

Risk 29
Severity
7.1
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server: MFA recovery code single-use bypass via concurrent requests

Risk 12
Severity
2.1
EPSS
0.03%
First published (updated )

parseplatform Parse-server Node.jsParse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter

Risk 53
Severity
8.6
EPSS
0.04%
First published (updated )

parseplatform Parse-server Node.jsParse Server: Denial of service via unindexed database query for unconfigured auth providers

Risk 33
Severity
8.7
EPSS
0.08%
First published (updated )

parseplatform Parse-server Node.jsParse Server: Session update endpoint allows overwriting server-generated session fields

Risk 19
Severity
5.3
EPSS
0.01%
First published (updated )

parseplatform Parse-server Node.jsParse Server: LiveQuery subscription query depth bypass

Risk 31
Severity
8.2
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server: Query condition depth bypass via pre-validation transform pipeline

Risk 33
Severity
8.7
EPSS
0.04%
First published (updated )

parseplatform Parse-server Node.jsParse Server: Protected field change detection oracle via LiveQuery watch parameter

Risk 21
Severity
6.3
EPSS
0.03%
First published (updated )

parseplatform Parse-server Node.jsParse Server: LiveQuery bypasses CLP pointer permission enforcement

Risk 29
Severity
7.1
EPSS
0.01%
First published (updated )

parseplatform Parse-server Node.jsParse Server: Auth provider validation bypass on login via partial authData

Risk 47
Severity
7
EPSS
0.04%
First published (updated )

parseplatform Parse-server Node.jsParse Server: Email verification resend page leaks user existence

Risk 21
Severity
6.3
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

parseplatform Parse-server Node.jsParse Server leaks protected fields via LiveQuery afterEvent trigger

Risk 31
Severity
8.2
EPSS
0.02%
First published (updated )

parseplatform Parse-server Node.jsParse Server affected by empty authData bypassing credential requirement on signup

Risk 23
Severity
6.9
EPSS
0.01%
First published (updated )

parseplatform Parse-server Node.jsParse Server: LiveQuery subscription with invalid regular expression crashes server

Risk 31
Severity
7.5
EPSS
0.03%
First published (updated )

parseplatform Parse-server Node.jsParse Server session creation endpoint allows overwriting server-generated session fields

Risk 16
Severity
4.3
EPSS
0.01%
First published (updated )

parseplatform Parse-server Node.jsParse Server vulnerable to schema poisoning via prototype pollution in deep copy

Risk 31
Severity
5.3
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203