Vulnerabilities in parse-community

127 results
Vexday analysis

Com 119 CVEs catalogadas e 18 classificadas como críticas, o ecossistema parse-community apresenta uma superfície de ataque relevante, especialmente considerando que 21 vulnerabilidades surgiram nos últimos 90 dias — sinal de atividade recente de descoberta. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, o que reduz a urgência imediata, mas não elimina o risco: o CVE-2022-24760 concentra o maior score EPSS observado (0,4908), indicando probabilidade não trivial de exploração. O tipo de falha mais recorrente é CWE-863 (Incorrect Authorization), sugerindo que controles de autorização inadequados são um padrão estrutural a ser endereçado em revisões de código e configuração. A presença de 2 CVEs com PoC pública reforça a necessidade de priorizar correções mesmo na ausência de exploração confirmada.

CVE-2026-30939HIGHParse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain ResolutionEPSS 0.5%CVE-2026-32944HIGHParse Server crash via deeply nested query condition operatorsEPSS 0.5%CVE-2022-39225MEDIUMParse Server subject to Incorrect Resource Transfer Between SpheresEPSS 0.5%CVE-2026-64627MEDIUMParse Server 9.0.0 Schema Disclosure via GraphQL Variable CoercionEPSS 0.5%CVE-2026-33409HIGHParse Server: Auth provider validation bypass on login via partial authDataEPSS 0.5%CVE-2026-30941HIGHParse Server has a NoSQL injection via token type in password reset and email verification endpointsEPSS 0.5%CVE-2026-33539HIGHParse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapterEPSS 0.5%CVE-2026-33498HIGHParse Server: Query condition depth bypass via pre-validation transform pipelineEPSS 0.5%CVE-2026-27595CRITICALParse Dashboard has incomplete authentication on AI Agent endpointEPSS 0.4%CVE-2026-30925HIGHParse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQueryEPSS 0.4%CVE-2026-31875HIGHParse Server MFA recovery codes not consumed after useEPSS 0.4%CVE-2026-30949HIGHParse Server is missing audience validation in Keycloak authentication adapterEPSS 0.4%CVE-2026-30947HIGHParse Server ha a bypass of class-level permissions in LiveQueryEPSS 0.4%CVE-2026-31828MEDIUMParse Server has an LDAP injection via unsanitized user input in DN and group filter constructionEPSS 0.4%CVE-2026-33163HIGHParse Server leaks protected fields via LiveQuery afterEvent triggerEPSS 0.4%CVE-2025-67727MEDIUMParse Server GitHub CI workflow vulnerable to RCE through Improper Privilege ManagementEPSS 0.4%CVE-2026-31856CRITICALParse Server has a SQL injection via `Increment` operation on nested object field in PostgreSQLEPSS 0.4%CVE-2026-31871CRITICALParse Server has a SQL Injection via dot-notation sub-key name in `Increment` operation on PostgreSQLEPSS 0.4%CVE-2024-47183HIGHParse Server's custom object ID allows to acquire role privilegesEPSS 0.4%CVE-2025-64502MEDIUMParse Server allows public `explain` queries which may expose sensitive database performance information and schema detailsEPSS 0.4%