mtrezza
8 credited records · 8 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2026-101042No exploit | Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identityparse-community · parse-server · CWE-287 | High7.4 | — | 0.2% | 3 days ago |
28Monitor | CVE-2026-100632No exploit | Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQueryparse-community · parse-server · CWE-200 | High7.1 | — | 0.3% | 4 days ago |
34Monitor | CVE-2026-100631No exploit | Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injectionparse-community · parse-server · CWE-943 | High8.7 | — | 0.4% | 4 days ago |
36Monitor | CVE-2026-87806No exploit | Parse Server 9.0.0 Authentication Bypass via LDAP Empty Passwordparse-community · parse-server · CWE-287 | Critical9.1 | — | 0.5% | Sep 9, 2026 |
25Monitor | CVE-2026-66009No exploit | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messagesparse-community · parse-server · CWE-209 | Medium6.3 | — | 0.4% | Jul 24, 2026 |
25Monitor | CVE-2026-66008No exploit | Parse Server 9.0.0 Information Disclosure via GraphQL Error Messagesparse-community · parse-server · CWE-209 | Medium6.3 | — | 0.6% | Jul 24, 2026 |
27Monitor | CVE-2026-64627No exploit | Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercionparse-community · parse-server · CWE-209 | Medium6.9 | — | 0.5% | Jul 21, 2026 |
8Monitor | CVE-2026-61448No exploit | Parse Server 9.0.0 Stored XSS via malformed Content-Typeparse-community · parse-server · CWE-434 | Low2.1 | — | 0.4% | Jul 11, 2026 |
- CVE-2026-10104229Monitor
Parse Server 9.0.0 Authentication Bypass via Unverified Provider Identity
HighCVSS 7.4No exploitEPSS 0%parse-community · parse-server3 days ago
- CVE-2026-10063228Monitor
Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery
HighCVSS 7.1No exploitEPSS 0%parse-community · parse-server4 days ago
- CVE-2026-10063134Monitor
Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection
HighCVSS 8.7No exploitEPSS 0%parse-community · parse-server4 days ago
- CVE-2026-8780636Monitor
Parse Server 9.0.0 Authentication Bypass via LDAP Empty Password
CriticalCVSS 9.1No exploitEPSS 1%parse-community · parse-serverSep 9, 2026
- CVE-2026-6600925Monitor
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
MediumCVSS 6.3No exploitEPSS 0%parse-community · parse-serverJul 24, 2026
- CVE-2026-6600825Monitor
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
MediumCVSS 6.3No exploitEPSS 1%parse-community · parse-serverJul 24, 2026
- CVE-2026-6462727Monitor
Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion
MediumCVSS 6.9No exploitEPSS 0%parse-community · parse-serverJul 21, 2026
- CVE-2026-614488Monitor
Parse Server 9.0.0 Stored XSS via malformed Content-Type
LowCVSS 2.1No exploitEPSS 0%parse-community · parse-serverJul 11, 2026