6.9

CVSS4.0

CVE-2026-23923 - Unauthenticated arbitrary PHP class instantiation

An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.

๐Ÿ“… Published: March 24, 2026, 6:29 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:27 p.m.

2.1

CVSS4.0

CVE-2026-33624 - Parse Server: MFA recovery code single-use bypass via concurrent requests

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.60 and 9.6.0-alpha.54, an attacker who obtains a user's password and a single MFA recovery code can reuse that recovery code an unlimited number of times by sending concurreโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:28 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:18 p.m.

8.7

CVSS4.0

CVE-2026-23921 - Blind, read-only SQL injection in Zabbix API via sortfield parameter

A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data throuโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:28 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 3:55 a.m.

7.7

CVSS4.0

CVE-2026-23920 - Host and event action script regex validation can be bypassed in certain situations, leading to potโ€ฆ

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.

๐Ÿ“… Published: March 24, 2026, 6:27 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 3:55 a.m.

8.6

CVSS4.0

CVE-2026-33539 - Parse Server: SQL injection via aggregate and distinct field names in PostgreSQL adapter

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL database by injecting SQL metacharacters into field name parโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:26 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 7:52 p.m.

7.1

CVSS4.0

CVE-2026-23919 - Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been releasedโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:26 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 7:06 a.m.

8.7

CVSS4.0

CVE-2026-33538 - Parse Server: Denial of service via unindexed database query for unconfigured auth providers

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.58 and 9.6.0-alpha.52, an unauthenticated attacker can cause denial of service by sending authentication requests with arbitrary, unconfigured provider names. The server exeโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:24 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:18 p.m.

5.3

CVSS4.0

CVE-2026-33527 - Parse Server: Session update endpoint allows overwriting server-generated session fields

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.57 and 9.6.0-alpha.48, an authenticated user can overwrite server-generated session fields such as expiresAt and createdWith when updating their own session via the REST APIโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:22 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:18 p.m.

8.2

CVSS4.0

CVE-2026-33508 - Parse Server: LiveQuery subscription query depth bypass

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.56 and 9.6.0-alpha.45, Parse Server's LiveQuery component does not enforce the requestComplexity.queryDepth configuration setting when processing WebSocket subscription requโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:21 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 12:18 p.m.

8.7

CVSS4.0

CVE-2026-33498 - Parse Server: Query condition depth bypass via pre-validation transform pipeline

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.55 and 9.6.0-alpha.44, an attacker can send an unauthenticated HTTP request with a deeply nested query containing logical operators to permanently hang the Parse Server procโ€ฆ

๐Ÿ“… Published: March 24, 2026, 6:18 p.m. ๐Ÿ”„ Last Modified: March 26, 2026, 7:52 p.m.
Total resulsts: 349182
Page 938 of 34,919
ยซ previous page ยป next page
Filters