GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            14 advisories
        Filter by severity
        
      
      
    
                    
                      Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62374
                      
                      was published
                        for
                        
                          parse
                        
                        (npm)
                      Oct 14, 2025 
                    
                  
                    
                      Parse Server exposes the data schema via GraphQL API
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53364
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Jul 10, 2025 
                    
                  
                    
                      Parse Server has an OAuth login vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-30168
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Mar 21, 2025 
                    
                  
                    
                      Parse Server's custom object ID allows to acquire role privileges
                    
                      
  High
                    
                
                      
                        CVE-2024-47183
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Oct 4, 2024 
                    
                  
                    
                      ZDI-CAN-23894: Parse Server literalizeRegexPart SQL Injection Authentication Bypass Vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2024-39309
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Jul 1, 2024 
                    
                  
                    
                      Server crashes on invalid Cloud Function or Cloud Job name
                    
                      
  Critical
                    
                
                      
                        CVE-2024-29027
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Mar 19, 2024 
                    
                  
                    
                      ZDI-CAN-19105: Parse Server literalizeRegexPart SQL Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2024-27298
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Mar 1, 2024 
                    
                  
                    
                      Parse Server may crash when uploading file without extension
                    
                      
  High
                    
                
                      
                        CVE-2023-46119
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Oct 24, 2023 
                    
                  
                    
                      Trigger `beforeFind` not invoked in internal query pipeline when fetching pointer
                    
                      
  High
                    
                
                      
                        CVE-2023-41058
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Sep 4, 2023 
                    
                  
                    
                      Parse Server vulnerable to remote code execution via MongoDB BSON parser through prototype pollution
                    
                      
  Critical
                    
                
                      
                        CVE-2023-36475
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Jun 30, 2023 
                    
                  
                    
                      Phishing attack vulnerability by uploading malicious HTML file
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-32689
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      May 31, 2023 
                    
                  
                    
                      Invalid push request payload crashes Parse Server
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-32688
                      
                      was published
                        for
                        
                          parse-server-push-adapter
                        
                        (npm)
                      May 22, 2023 
                    
                  
                    
                      Invalid file request can crash server
                    
                      
  High
                    
                
                      
                        CVE-2022-31089
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Jun 20, 2022 
                    
                  
                    
                      Command injection in Parse Server through prototype pollution
                    
                      
  Critical
                    
                
                      
                        CVE-2022-24760
                      
                      was published
                        for
                        
                          parse-server
                        
                        (npm)
                      Mar 11, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API