Manuel
72 exploits
Active since Sep 2021
Parse Server: Denial of service via unindexed database query for unconfigured auth providers
CVSS 7.5
Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter
CVSS 7.2
Parse Server: MFA recovery code single-use bypass via concurrent requests
CVSS 2.7
Parse Server: Auth data exposed via /users/me endpoint
CVSS 6.5
Parse Server File Uploads - Stored Cross-Site Scripting Filter Bypass
CVSS 7.6
Parse Server <8.6.3/9.1.1-alpha.4 - Auth Bypass
CVSS 9.1
Parse Dashboard 7.3.0-alpha.42-9.0.0-alpha.7 - Privilege Escalation
CVSS 5.3
parse-server < 4.10.3 - Denial of Service via Invalid Explain Query Option
CVSS 7.5
Parse Server <4.10.11, <5.2.2 - Auth Bypass
CVSS 8.6
Parse Server <4.10.12, <5.2.3 - DoS
CVSS 7.5
parse-server < 4.10.13 - Information Exposure via LiveQuery Protected Fields
CVSS 8.2
Parse Server <4.10.14-5.2.5 - Info Disclosure
CVSS 8.6
parse-server < 5.4.1 - Authentication Bypass via X-Forwarded-For Header Spoofing
CVSS 8.7
Parse Server < 5.5.2 - Remote Code Execution via Prototype Pollution
CVSS 9.8
Parse Server < 5.5.5 - Always-Incorrect Control Flow Implementation in beforeFind Trigger
CVSS 7.5
Parse Server <5.5.6,6.3.1 - Info Disclosure
CVSS 7.5
Parse Server <6.5.0, <7.0.0-alpha.20 - SQL Injection
CVSS 10.0
Parse Server < 6.5.5 - Remote Code Execution via Cloud Function or Job Name Injection
CVSS 9.0
Parse Server <6.5.9, <7.3.0 - Privilege Escalation
CVSS 8.1
Parse Server <7.5.2-8.0.2 - Auth Bypass
CVSS 6.9
Parse Server 4.2.0-7.5.3 and 8.0.0-8.3.1-alpha.1 - Server-Side Request Forgery via File Upload URI Parameter
CVSS 7.5
homarr < 1.43.3 - Stored Cross-Site Scripting via Malicious SVG File Upload
CVSS 8.1