UBUNTU-CVE-2025-3279

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS ...

Continue Reading
MAL-2025-5627 Malicious code in graphql-commons (npm)

The package communicates with a domain associated with malicious activity. -= Per source details. Do not edit below this line.=- Source: ossf-package-analysis (b7c583ae9a5f16200bfe90e125da19776e40148 ...

Continue Reading
MAL-2025-5624 Malicious code in cmr-graphql (npm)

The package communicates with a domain associated with malicious activity. -= Per source details. Do not edit below this line.=- Source: ghsa-malware (b805bd73c447ee03b3330e1a1ce27c4b8edef17d58376cd0 ...

Continue Reading
GHSA-48Q3-PRGV-GM4W Parse Server exposes the data schema via GraphQL API

Impact The Parse Server GraphQL API previously allowed public access to the GraphQL schema without requiring a session token or the master key. While schema introspection reveals only metadata and not ...

Continue Reading
CVE-2025-53364

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed pu ...

Continue Reading
CVE-2025-46732 OpenCTI’s GraphQL IDOR enables authenticated users to modify or delete notifications of other users

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in the GrapQL NotificationLineNotificationMarkReadMut ...

Continue Reading
CVE-2025-46732 OpenCTI’s GraphQL IDOR enables authenticated users to modify or delete notifications of other users

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.6.6, an IDOR vulnerability in the GrapQL NotificationLineNotificationMarkReadMut ...

Continue Reading
BIT-PARSE-2025-53364 Parse Server exposes the data schema via GraphQL API

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Starting in 5.3.0 and before 7.5.3 and 8.2.2, the Parse Server GraphQL API previously allowed pu ...

Continue Reading

Back to Main

Subscribe for the latest news: