GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
34 advisories
Filter by severity
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers
Moderate
CVE-2026-47248
was published
for
parse-server
(npm)
May 29, 2026
Parse Server's Endpoint `/sessions/me` bypasses `_Session` `protectedFields`
Moderate
CVE-2026-39381
was published
for
parse-server
(npm)
Apr 8, 2026
Parse Server has a login timing side-channel reveals user existence
Moderate
CVE-2026-39321
was published
for
parse-server
(npm)
Apr 8, 2026
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value
Moderate
CVE-2026-34595
was published
for
parse-server
(npm)
Apr 1, 2026
Parse Server has a session field immutability bypass via falsy-value guard
Moderate
CVE-2026-34574
was published
for
parse-server
(npm)
Apr 1, 2026
GraphQL API endpoint ignores CORS origin restriction
Moderate
CVE-2026-34373
was published
for
parse-server
(npm)
Mar 30, 2026
Parse Server's Session Update endpoint allows overwriting server-generated session fields
Moderate
CVE-2026-33527
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server has a protected field change detection oracle via LiveQuery watch parameter
Moderate
CVE-2026-33429
was published
for
parse-server
(npm)
Mar 20, 2026
Parse Server email verification resend page leaks user existence
Moderate
CVE-2026-33323
was published
for
parse-server
(npm)
Mar 19, 2026
Parse Server affected by empty authData bypassing credential requirement on signup
Moderate
CVE-2026-33042
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server LiveQuery subscription with invalid regular expression crashes server
Moderate
CVE-2026-32770
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server session creation endpoint allows overwriting server-generated session fields
Moderate
CVE-2026-32742
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server vulnerable to schema poisoning via prototype pollution in deep copy
Moderate
CVE-2026-32878
was published
for
parse-server
(npm)
Mar 17, 2026
Parse Server's GraphQL WebSocket endpoint bypasses security middleware
Moderate
CVE-2026-32594
was published
for
parse-server
(npm)
Mar 13, 2026
Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint
Moderate
CVE-2026-32269
was published
for
parse-server
(npm)
Mar 13, 2026
Parse Server has a SQL injection via query field name when using PostgreSQL
Moderate
CVE-2026-32234
was published
for
parse-server
(npm)
Mar 12, 2026
Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause
Moderate
CVE-2026-32098
was published
for
parse-server
(npm)
Mar 12, 2026
Parse Server vulnerable to user enumeration via email verification endpoint
Moderate
CVE-2026-31901
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types
Moderate
CVE-2026-31868
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server vulnerable to LDAP injection via unsanitized user input in DN and group filter construction
Moderate
CVE-2026-31828
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a rate limit bypass via batch request endpoint
Moderate
CVE-2026-30972
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placement
Moderate
CVE-2026-30938
was published
for
parse-server
(npm)
Mar 10, 2026
Parse Server: GraphQL `__type` introspection bypass via inline fragments when public introspection is disabled
Moderate
CVE-2026-30854
was published
for
parse-server
(npm)
Mar 9, 2026
Parse Server: File metadata endpoint bypasses `beforeFind` / `afterFind` trigger authorization
Moderate
CVE-2026-30850
was published
for
parse-server
(npm)
Mar 9, 2026
Parse Server: `PagesRouter` path traversal allows reading files outside configured pages directory
Moderate
CVE-2026-30848
was published
for
parse-server
(npm)
Mar 9, 2026
ProTip!
Advisories are also available from the
GraphQL API