GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
57
GitHub Actions
50
Go
3,767
Maven
5,000+
npm
5,000+
NuGet
937
pip
4,999
Pub
13
RubyGems
1,058
Rust
1,347
Swift
54
Unreviewed advisories
All unreviewed
5,000+
92 advisories
Filter by severity
parse-server: MFA SMS one-time password accepted twice under concurrent login
Low
CVE-2026-43930
was published
for
parse-server
(npm)
May 5, 2026
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
Moderate
CVE-2026-39381
was published
for
parse-server
(npm)
Apr 8, 2026
Parse Server has a login timing side-channel reveals user existence
Moderate
CVE-2026-39321
was published
for
parse-server
(npm)
Apr 8, 2026
Parse Server: File upload Content-Type override via extension mismatch
Low
CVE-2026-35200
was published
for
parse-server
(npm)
Apr 4, 2026
Parse Server exposes auth data via verify password endpoint
High
CVE-2026-34215
was published
for
parse-server
(npm)
Mar 29, 2026
Parser Server's streaming file download bypasses afterFind file trigger authorization
High
CVE-2026-34784
was published
for
parse-server
(npm)
Apr 1, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value
Moderate
CVE-2026-34595
was published
for
parse-server
(npm)
Apr 1, 2026
Parse Server has a session field immutability bypass via falsy-value guard
Moderate
CVE-2026-34574
was published
for
parse-server
(npm)
Apr 1, 2026
parse-server has GraphQL complexity validator exponential fragment traversal DoS
High
CVE-2026-34573
was published
for
parse-server
(npm)
Mar 31, 2026
parse-server has cloud function validator bypass via prototype chain traversal
Critical
CVE-2026-34532
was published
for
parse-server
(npm)
Mar 31, 2026
GraphQL API endpoint ignores CORS origin restriction
Moderate
CVE-2026-34373
was published
for
parse-server
(npm)
Mar 30, 2026
LiveQuery protected field leak via shared mutable state across concurrent subscribers
High
CVE-2026-34363
was published
for
parse-server
(npm)
Mar 30, 2026
Parse Server has an MFA single-use token bypass via concurrent authData login requests
Low
CVE-2026-34224
was published
for
parse-server
(npm)
Mar 29, 2026
Parse Server's Session Update endpoint allows overwriting server-generated session fields
Moderate
CVE-2026-33527
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server LiveQuery subscription query depth bypass
High
CVE-2026-33508
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server has a query condition depth bypass via pre-validation transform pipeline
High
CVE-2026-33498
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server has a protected field change detection oracle via LiveQuery watch parameter
Moderate
CVE-2026-33429
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server's LiveQuery bypasses CLP pointer permission enforcement
High
CVE-2026-33421
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server has an auth provider validation bypass on login via partial authData
High
CVE-2026-33409
was published
for
parse-server
(npm)
Mar 19, 2026
Parse Server email verification resend page leaks user existence
Moderate
CVE-2026-33323
was published
for
parse-server
(npm)
Mar 19, 2026
Parse Server exposes auth data via /users/me endpoint
High
CVE-2026-33627
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server: MFA recovery code single-use bypass via concurrent requests
Low
CVE-2026-33624
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server has SQL Injection through aggregate and distinct field names in PostgreSQL adapter
High
CVE-2026-33539
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server: Denial of Service via unindexed database query for unconfigured auth providers
High
CVE-2026-33538
was published
for
parse-server
(npm)
Mar 24, 2026
ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
Critical
CVE-2024-27298
was published
for
parse-server
(npm)
Mar 1, 2024
ProTip!
Advisories are also available from the
GraphQL API