Vulnerabilidades em parse-community

126 resultados
Análise Vexday

Com 119 CVEs catalogadas e 18 classificadas como críticas, o ecossistema parse-community apresenta uma superfície de ataque relevante, especialmente considerando que 21 vulnerabilidades surgiram nos últimos 90 dias — sinal de atividade recente de descoberta. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero registros no CISA KEV, o que reduz a urgência imediata, mas não elimina o risco: o CVE-2022-24760 concentra o maior score EPSS observado (0,4908), indicando probabilidade não trivial de exploração. O tipo de falha mais recorrente é CWE-863 (Incorrect Authorization), sugerindo que controles de autorização inadequados são um padrão estrutural a ser endereçado em revisões de código e configuração. A presença de 2 CVEs com PoC pública reforça a necessidade de priorizar correções mesmo na ausência de exploração confirmada.

CVE-2022-41879HIGHParse Server subject to Prototype pollution via Cloud Code WebhooksEPSS 0.8%CVE-2020-26288HIGHParse Server stores password in plain textEPSS 0.8%CVE-2022-39313HIGHParse Server crashes when receiving file download request with invalid byte rangeEPSS 0.7%CVE-2023-22474HIGHParse Server is vulnerable to authentication bypass via spoofingEPSS 0.7%CVE-2022-24901HIGHAuthentication bypass and denial of service (DoS) vulnerabilities in Apple Game Center auth adapter EPSS 0.7%CVE-2023-32689MEDIUMParse Server vulnerable to phishing attack vulnerability that involves uploading malicious HTML fileEPSS 0.6%CVE-2026-32248CRITICALParse Server: Account takeover via operator injection in authentication data identifierEPSS 0.6%CVE-2023-41058HIGHTrigger `beforeFind` not invoked in internal query pipeline in parse-serverEPSS 0.6%CVE-2025-64430HIGHParse Server Vulnerable to Server-Side Request Forgery (SSRF) in File Upload via URI FormatEPSS 0.6%CVE-2026-47138HIGHParse Server: Pre-authentication denial of service via client version header regex backtrackingEPSS 0.6%CVE-2026-30946HIGHParse Server affected by denial-of-service via unbounded query complexity in REST and GraphQL APIEPSS 0.6%CVE-2026-32770MEDIUMParse Server: LiveQuery subscription with invalid regular expression crashes serverEPSS 0.5%CVE-2026-30863CRITICALParse Server: JWT audience validation bypass in Google, Apple, and Facebook authentication adaptersEPSS 0.5%CVE-2026-32886HIGHParse Server's Cloud function dispatch crashes server via prototype chain traversalEPSS 0.5%CVE-2026-30939HIGHParse Server has Denial of Service (DoS) and Cloud Function Dispatch Bypass via Prototype Chain ResolutionEPSS 0.5%CVE-2026-32944HIGHParse Server crash via deeply nested query condition operatorsEPSS 0.5%CVE-2026-34573HIGHParse Server: GraphQL complexity validator exponential fragment traversal DoSEPSS 0.5%CVE-2022-39231LOWParse Server subject to Improper Authentication allowing Auth adapter app ID validation to be circumventedEPSS 0.5%CVE-2026-33409HIGHParse Server: Auth provider validation bypass on login via partial authDataEPSS 0.5%CVE-2026-30941HIGHParse Server has a NoSQL injection via token type in password reset and email verification endpointsEPSS 0.5%