Known vulnerabilities in Parse Server - page 5

Software: Parse Server
Software CPE: cpe:2.3:a:parse_community:parse_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 102
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Parse Server Parse Server is affected by 102 known vulnerabilities: 19 high, 54 medium, 29 low Critical High Medium Low

Vulnerabilities (102)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU120252 - Permissions, Privileges, and Access Controls
CVE-2025-67727
CWE-264 Medium
No
No
8.6.0 23.12.2025 SB2025122314
#VU120251 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-68115
CWE-79 Low
No
No
8.6.1, 9.1.0 23.12.2025 SB2025122315
#VU120250 - Server-Side Request Forgery (SSRF)
CVE-2025-68150
CWE-918 Medium
No
No
8.6.2, 9.1.1 23.12.2025 SB2025122316
#VU118137 - Server-Side Request Forgery (SSRF)
CVE-2025-64430
CWE-918 Medium
No
No
7.5.4, 8.4.0 05.11.2025 SB2025110554
#VU86982 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-27298
CWE-89 High
No
No
6.5.0 04.03.2024 SB2024030404
SB2024070813
#VU82312 - Improper input validation
CVE-2023-46119
CWE-20 Medium
No
No
5.5.6, 6.3.1 24.10.2023 SB2023102404
#VU80441 - Improper Access Control
CVE-2023-41058
CWE-284 Medium
No
No
5.5.5, 6.2.2 05.09.2023 SB2023090542
#VU77794 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-36475
CWE-1321 High
No
No
5.5.2, 6.2.1 29.06.2023 SB2023062920
#VU71664 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2023-22474
CWE-451 Medium
No
No
5.4.1 31.01.2023 SB2023013102
#VU69483 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-39396
CWE-94 High
No
No
4.10.18, 5.3.1 22.11.2022 SB2022112219
#VU69482 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-41878
CWE-94 Low
No
No
4.10.19, 5.3.2 22.11.2022 SB2022112218
#VU69481 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-41879
CWE-94 Low
No
No
4.10.20, 5.3.3 22.11.2022 SB2022112217
#VU68343 - Improper input validation
CVE-2022-39313
CWE-20 Medium
No
No
4.10.17, 5.2.8 17.10.2022 SB2022101703
#VU67068 - Exposure of sensitive information to an unauthorized actor
CVE-2022-36079
CWE-200 High
No
No
4.10.14, 5.2.5 07.09.2022 SB2022090731
#VU64723 - Improper Certificate Validation
CVE-2022-31083
CWE-295 High
No
No
4.10.11 27.06.2022 SB2022062736
#VU61372 - Improper Control of Generation of Code ('Code Injection')
CWE-94 High
No
No
5.0.0 15.03.2022 SB2022031509
#VU61288 - Command injection
CWE-77 High
No
No
4.10.7 14.03.2022 SB2022031417
#VU57060 - Exposure of sensitive information to an unauthorized actor
CVE-2021-41109
CWE-200 Medium
No
No
4.10.4 05.10.2021 SB2021100512
#VU56933 - Exposure of sensitive information to an unauthorized actor
CWE-200 Low
No
No
4.10.4 30.09.2021 SB2021093003
#VU56141 - Exposure of sensitive information to an unauthorized actor
CVE-2021-39138
CWE-200 Medium
No
No
4.5.1 27.08.2021 SB2021082712


Showing elements 81 - 100 out of 102