cve.li

Recent

CVE-2026-23919CWE-488

Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

Published 2026-03-24 by Zabbix

CVE-2026-33538CWE-400

Parse Server: Denial of service via unindexed database query for unconfigured auth providers

Published 2026-03-24 by GitHub_M

CVE-2026-33527CWE-863

Parse Server: Session update endpoint allows overwriting server-generated session fields

Published 2026-03-24 by GitHub_M

CVE-2026-33508CWE-674

Parse Server: LiveQuery subscription query depth bypass

Published 2026-03-24 by GitHub_M

CVE-2026-33498CWE-674

Parse Server: Query condition depth bypass via pre-validation transform pipeline

Published 2026-03-24 by GitHub_M

CVE-2026-33429CWE-203

Parse Server: Protected field change detection oracle via LiveQuery watch parameter

Published 2026-03-24 by GitHub_M

CVE-2026-33421CWE-863

Parse Server: LiveQuery bypasses CLP pointer permission enforcement

Published 2026-03-24 by GitHub_M

CVE-2026-33409CWE-287

Parse Server: Auth provider validation bypass on login via partial authData

Published 2026-03-24 by GitHub_M

CVE-2026-2417CWE-306

Missing Authentication for Critical Function in Pharos Controls Mosaic Show Controller

Published 2026-03-24 by icscert

CVE-2026-33323CWE-204

Parse Server: Email verification resend page leaks user existence

Published 2026-03-24 by GitHub_M

Load more ↓