Manuel
72 exploits
Active since Sep 2021
Parse Server < 4.10.7 - Remote Code Execution via Prototype Pollution in DatabaseController.js
CVSS 10.0
parse-server < 4.10.13 - Information Exposure via LiveQuery Protected Fields
CVSS 8.2
Parse Server <4.10.14-5.2.5 - Info Disclosure
CVSS 8.6
Parse Server < 5.5.2 - Remote Code Execution via Prototype Pollution
CVSS 9.8
Parse Server <5.5.6,6.3.1 - Info Disclosure
CVSS 7.5
Parse Server <6.5.0, <7.0.0-alpha.20 - SQL Injection
CVSS 10.0
Parse Server < 6.5.5 - Remote Code Execution via Cloud Function or Job Name Injection
CVSS 9.0
Parse Server < 6.5.7 and 7.0.0-7.1.0 - SQL Injection via PostgreSQL Configuration
CVSS 9.8
Parse Server < 6.5.7 and 7.0.0-7.1.0 - SQL Injection via PostgreSQL Configuration
CVSS 9.8
Parse Server <6.5.9, <7.3.0 - Privilege Escalation
CVSS 8.1
Parse Server <7.5.2-8.0.2 - Auth Bypass
CVSS 6.9
Parse Server 4.2.0-7.5.3 and 8.0.0-8.3.1-alpha.1 - Server-Side Request Forgery via File Upload URI Parameter
CVSS 7.5
Parse Server <8.6.3/9.1.1-alpha.4 - Auth Bypass
CVSS 9.1
Parse Server File Uploads - Stored Cross-Site Scripting Filter Bypass
CVSS 7.6
Parse Server: Email verification resend page leaks user existence
CVSS 5.3
Parse Server: Auth provider validation bypass on login via partial authData
CVSS 9.1
Parse Server: LiveQuery bypasses CLP pointer permission enforcement
CVSS 6.5
Parse Server: Protected field change detection oracle via LiveQuery watch parameter
CVSS 5.3
Parse Server: Query condition depth bypass via pre-validation transform pipeline
CVSS 7.5
Parse Server: LiveQuery subscription query depth bypass
CVSS 7.5
Parse Server: Session update endpoint allows overwriting server-generated session fields
CVSS 4.3
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
CVSS 7.5
Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter
CVSS 7.2
Parse Server: MFA recovery code single-use bypass via concurrent requests
CVSS 2.7
Parse Server: Auth data exposed via /users/me endpoint
CVSS 6.5