Known vulnerabilities in Parse Server

Software: Parse Server
Software CPE: cpe:2.3:a:parse_community:parse_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 102
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Parse Server Parse Server is affected by 102 known vulnerabilities: 19 high, 54 medium, 29 low Critical High Medium Low

Vulnerabilities (102)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135973 - Unrestricted Upload of File with Dangerous Type
CWE-434 Low
No
No
8.6.84, 9.10.0 alpha.2 30.06.2026 SB2026063054
#VU135972 - Exposure of sensitive information to an unauthorized actor
CVE-2026-57481
CWE-200 Low
No
No
8.6.83, 9.9.1 alpha.13 30.06.2026 SB2026063053
#VU135971 - Inefficient Algorithmic Complexity
CVE-2026-57480
CWE-407 Medium
No
No
8.6.82, 9.9.1 alpha.12 30.06.2026 SB2026063052
#VU135970 - Unrestricted Upload of File with Dangerous Type
CVE-2026-55778
CWE-434 Low
No
No
8.6.81, 9.9.1 alpha.11 30.06.2026 SB2026063051
#VU135969 - Authorization Bypass Through User-Controlled Key
CVE-2026-53726
CWE-639 Medium
No
No
8.6.80, 9.9.1 alpha.6 30.06.2026 SB2026063050
#VU135968 - Exposure of sensitive information to an unauthorized actor
CVE-2026-53725
CWE-200 Low
No
No
9.9.1 alpha.5 30.06.2026 SB2026063049
#VU135967 - Incorrect Authorization
CVE-2026-50008
CWE-863 Medium
No
No
9.9.1 alpha.3 30.06.2026 SB2026063048
#VU129731 - Resource exhaustion
CVE-2026-33538
CWE-400 Medium
No
No
8.6.58, 9.6.0 alpha.52 05.05.2026 SB2026050558
#VU129684 - Allocation of Resources Without Limits or Throttling
CVE-2026-30946
CWE-770 Medium
No
No
8.6.15, 9.5.2 alpha.2 05.05.2026 SB2026050557
#VU129682 - Exposure of sensitive information to an unauthorized actor
CVE-2026-33627
CWE-200 Medium
No
No
8.6.61, 9.6.0 alpha.55 05.05.2026 SB2026050556
#VU125034 - Incorrect Authorization
CVE-2026-39381
CWE-863 Low
No
No
8.6.75, 9.8.0 alpha.7 07.04.2026 SB2026040791
#VU124965 - Inclusion of Functionality from Untrusted Control Sphere
CWE-829 Low
No
No
4.10.0 06.04.2026 SB2026040790
#VU124966 - Improper Access Control
CVE-2025-64502
CWE-284 Medium
No
No
8.5.0 alpha.5 06.04.2026 SB2026040789
#VU124967 - Insufficient Verification of Data Authenticity
CVE-2026-27804
CWE-345 High
No
No
8.6.3, 9.3.1 alpha.4 06.04.2026 SB2026040788
#VU124968 - Incorrect Authorization
CVE-2026-29182
CWE-863 Low
No
No
8.6.4, 9.4.1 alpha.3 06.04.2026 SB2026040787
#VU124969 - Incorrect Authorization
CVE-2026-30228
CWE-863 Low
No
No
8.6.5, 9.5.0 alpha.3 06.04.2026 SB2026040786
#VU124970 - Incorrect Authorization
CVE-2026-30229
CWE-863 Low
No
No
8.6.6, 9.5.0 alpha.4 06.04.2026 SB2026040785
#VU124971 - Information Exposure Through an Error Message
CVE-2026-30835
CWE-209 Medium
No
No
8.6.7, 9.5.0 alpha.6 06.04.2026 SB2026040784
#VU124972 - Improper Authentication
CVE-2026-30863
CWE-287 High
No
No
8.6.10, 9.5.0 alpha.11 06.04.2026 SB2026040783
#VU124973 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-30848
CWE-22 Medium
No
No
8.6.8, 9.5.0 alpha.8 06.04.2026 SB2026040782


Showing elements 1 - 20 out of 102