Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Parse Dashboard MEDIUM 6.5
CVE-2026-27609

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…

Mitigation only
Fix from $1,600 2026-02-25
Parse Dashboard MEDIUM 5.3
CVE-2026-27610

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the `ConfigKeyCache` uses…

Patch available
Fix from $1,600 2026-02-25
Parse Dashboard HIGH 8.1
CVE-2026-27608

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…

Mitigation only
Fix from $1,950 2026-02-25
Parse Dashboard HIGH 7.5
CVE-2026-27595

Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint…

Mitigation only
Fix from $1,950 2026-02-25
Parse Server MEDIUM 6.5
CVE-2025-68150

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.2 and 9.1.1-alpha.1, th…

Fix: 8.6.2+
Fix from $1,600 2025-12-16
Parse Server MEDIUM 6.1
CVE-2025-68115

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 8.6.1 and 9.1.0-alpha.3,…

Fix: 8.6.1+
Fix from $1,600 2025-12-16
Parse Server CRITICAL 9.8
CVE-2025-67727

Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior to 8.6.0-alpha.2, a GitHub CI …

Fix: after 8.5.0
Fix from $2,300 2025-12-12
Parse Javascript Sdk MEDIUM 6.5
CVE-2025-57324

parse is a package designed to parse JavaScript SDK. A Prototype Pollution vulnerability in the SingleInstanceStateController.initializeState functio…

Fix: after 5.3.0
Fix from $1,600 2025-09-24
Parse Server HIGH 8.1
CVE-2024-47183

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectI…

Fix: 6.5.9 / 7.3.0+
Fix from $1,950 2024-10-04
Parse Server CRITICAL 9.0
CVE-2024-29027

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, c…

Fix: 6.5.5+
Fix from $2,300 2024-03-19
Parse Server CRITICAL 10.0
CVE-2024-27298

parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL d…

Fix: 6.5.0+
Fix from $2,300 2024-03-01
Parse Server HIGH 7.5
CVE-2023-46119

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file wi…

Fix: 5.5.6 / 6.3.1+
Fix from $1,950 2023-10-25
Parse Server HIGH 7.5
CVE-2023-41058

Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked in certain conditions of `Par…

Fix: 5.5.5 / 6.2.2+
Fix from $1,950 2023-09-04
Parse Server CRITICAL 9.8
CVE-2023-36475

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacke…

Fix: 5.5.2 / 6.2.1+
Fix from $2,300 2023-06-28
Parse Server MEDIUM 6.5
CVE-2023-32689

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 5.4.4 and 6.1.1 are vulnera…

Fix: 5.4.4 / 6.1.1+
Fix from $1,600 2023-05-30
Parse Server Push Adapter HIGH 7.5
CVE-2023-32688

parse-server-push-adapter is the official Push Notification adapter for Parse Server. The Parse Server Push Adapter can crash Parse Server due to an …

Fix: 4.1.3+
Fix from $1,950 2023-05-27
Parse Server HIGH 8.1
CVE-2023-22474

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server uses the request header `x-forwa…

Fix: 5.4.1+
Fix from $1,950 2023-02-03
Parse Server CRITICAL 9.8
CVE-2022-41878

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.2 or 4.10.19, keywor…

Fix: 4.10.19 / 5.3.2+
Fix from $2,300 2022-11-10
Parse Server CRITICAL 9.8
CVE-2022-41879

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 5.3.3 or 4.10.20, a comp…

Fix: 4.10.20 / 5.3.3+
Fix from $2,300 2022-11-10
Parse Server CRITICAL 9.8
CVE-2022-39396EPSS 39%

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1…

Fix: 4.10.18 / 5.3.1+
Fix from $2,300 2022-11-10
Parse Server HIGH 7.5
CVE-2022-39313

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.17, and prior to 5.2.8…

Fix: 4.10.17 / 5.2.8+
Fix from $1,950 2022-10-24
Parse Server HIGH 7.5
CVE-2022-36079

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields (keys used internally by Pars…

Fix: 4.10.14 / 5.2.5+
Fix from $1,950 2022-09-07
Parse Server HIGH 8.2
CVE-2022-31112

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery d…

Fix: 4.10.13 / 5.2.4+
Fix from $1,950 2022-06-30
Parse Server HIGH 7.5
CVE-2022-31089

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions certain types of invalid…

Fix: 4.10.12 / 5.2.3+
Fix from $1,950 2022-06-27
Parse Server HIGH 7.5
CVE-2022-31083

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the cert…

Fix: 4.10.11 / 5.2.2+
Fix from $1,950 2022-06-17
Parse Server HIGH 7.5
CVE-2022-24901

Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making th…

Fix: 4.10.10 / 5.2.1+
Fix from $1,950 2022-05-04
Parse Server CRITICAL 10.0
CVE-2022-24760EPSS 49%

Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Ser…

Fix: 4.10.7+
Fix from $2,300 2022-03-12
Parse Server HIGH 7.5
CVE-2021-41109

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.4, for regular (non-Liv…

Fix: 4.10.4+
Fix from $1,950 2021-09-30
Parse Server HIGH 7.5
CVE-2021-39187

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes…

Fix: 4.10.3+
Fix from $1,950 2021-09-02
Parse Server MEDIUM 6.5
CVE-2021-39138

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Developers can use the REST API to signup use…

Fix: 4.5.1+
Fix from $1,600 2021-08-19