|
541
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and 9.9.1-alpha.1, an unauthenticated attacker who knows a publicly-kn…
Update
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-47138
|
2026-06-16 06:05 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
542
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Solidtime is an open-source time-tracking app. Prior to version 0.12.2, Solidtime defines an explicit invitations:view and members:view permissions that gates the official invitations and members API…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-47236
|
2026-06-16 06:05 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
543
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.3, the routeAllowList server option restricts …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-50008
|
2026-06-16 06:05 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
544
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.79 and 9.9.1-alpha.4, the default file upload extension blocklist can be …
Update
|
CWE-79 CWE-434
Cross-site Scripting Unrestricted Upload of File with Dangerous Type
|
CVE-2026-53724
|
2026-06-16 06:05 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
545
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to before version 9.9.1-alpha.5, apps that enable MFA and deny get on the _U…
Update
|
CWE-200
Information Exposure
|
CVE-2026-53725
|
2026-06-16 06:05 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
546
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.80 and 9.9.1-alpha.6, a relation query using the $relatedTo operator coul…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-53726
|
2026-06-16 06:05 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
547
|
- |
|
-
|
-
|
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.
New
|
-
|
CVE-2026-38060
|
2026-06-16 06:05 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
548
|
- |
|
-
|
-
|
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.
New
|
-
|
CVE-2026-38061
|
2026-06-16 06:05 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
549
|
- |
|
-
|
-
|
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.
New
|
-
|
CVE-2026-38062
|
2026-06-16 06:05 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
550
|
- |
|
-
|
-
|
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.
New
|
-
|
CVE-2026-38063
|
2026-06-16 06:05 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|