Vulnerabilidades em parse-community

127 resultados
Análise Vexday

Com 119 CVEs catalogadas e 18 classificadas como críticas, o ecossistema parse-community apresenta uma superfície de ataque relevante, especialmente considerando que 21 vulnerabilidades surgiram nos últimos 90 dias — sinal de atividade recente de descoberta. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, o que reduz a urgência imediata, mas não elimina o risco: o CVE-2022-24760 concentra o maior score EPSS observado (0,4908), indicando probabilidade não trivial de exploração. O tipo de falha mais recorrente é CWE-863 (Incorrect Authorization), sugerindo que controles de autorização inadequados são um padrão estrutural a ser endereçado em revisões de código e configuração. A presença de 2 CVEs com PoC pública reforça a necessidade de priorizar correções mesmo na ausência de exploração confirmada.

CVE-2026-34532CRITICALParse Server: Cloud function validator bypass via prototype chain traversalEPSS 0.3%CVE-2026-32269MEDIUMParse Server OAuth2 adapter app ID validation sends wrong token to introspection endpointEPSS 0.3%CVE-2026-53726MEDIUMParse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACLEPSS 0.3%CVE-2026-32728HIGHParse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entriesEPSS 0.3%CVE-2026-66009MEDIUMParse Server 9.0.0 Information Disclosure via GraphQL Error MessagesEPSS 0.3%CVE-2026-32242CRITICALParse Server OAuth2 adapter shares mutable state across providers via singleton instanceEPSS 0.3%CVE-2026-33527MEDIUMParse Server: Session update endpoint allows overwriting server-generated session fieldsEPSS 0.3%CVE-2026-53725MEDIUMParse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is deniedEPSS 0.3%CVE-2026-34595MEDIUMParse Server: LiveQuery protected-field guard bypass via array-like logical operator valueEPSS 0.3%CVE-2026-31868MEDIUMParse Server has Stored XSS via file upload of HTML-renderable file typesEPSS 0.2%CVE-2026-31901MEDIUMParse Server has user enumeration via email verification endpointEPSS 0.2%CVE-2026-43930LOWParse Server: MFA SMS one-time password accepted twice under concurrent loginEPSS 0.2%CVE-2026-39321MEDIUMParse Server has a login timing side-channel reveals user existenceEPSS 0.2%CVE-2026-27608CRITICALParse Dashboard Missing Authorization on Agent EndpointEPSS 0.2%CVE-2025-68115MEDIUMParse Server vulnerable to Cross-Site Scripting (XSS) via Unescaped Mustache Template VariablesEPSS 0.2%CVE-2026-30948HIGHParse Server has stored cross-site scripting (XSS) via SVG file uploadEPSS 0.2%CVE-2026-34574MEDIUMParse Server: Session field immutability bypass via falsy-value guardEPSS 0.2%CVE-2026-32943LOWParse Server has a password reset token single-use bypass via concurrent requestsEPSS 0.2%CVE-2026-34373MEDIUMParse Server: GraphQL API endpoint ignores CORS origin restrictionEPSS 0.2%CVE-2026-32234MEDIUMParse Server has a SQL injection via query field name when using PostgreSQLEPSS 0.2%