<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T05:00:21.980754+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-44896</id>
    <title>cnvd-2020-44896</title>
    <updated>2026-10-10T05:00:21.983911+00:00</updated>
    <content>cnvd-2020-44896</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-44896"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-42684</id>
    <title>EUVD-2026-42684</title>
    <updated>2026-10-10T05:00:21.983944+00:00</updated>
    <content>EUVD-2026-42684</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-42684"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15126</id>
    <title>fkie_cve-2020-15126</title>
    <updated>2026-10-10T05:00:21.983958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2020-15126"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-236h-rqv8-8q73</id>
    <title>GHSA-236h-rqv8-8q73 — GraphQL: Security breach on Viewer query</title>
    <updated>2026-10-10T05:00:21.983986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: parse-server</p>
<p>### Impact
An authenticated user using the viewer GraphQL query can bypass all read security on his User object and can also bypass all objects linked via relation or Pointer on his User object.</p>
<p>### Patches
This vulnerability has been patched in Parse Server 4.3.0.</p>
<p>### Workarounds
No</p>
<p>### References
See [commit 78239ac](https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa) for details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-236h-rqv8-8q73"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2020-15126</id>
    <title>gsd-2020-15126</title>
    <updated>2026-10-10T05:00:21.984012+00:00</updated>
    <content>gsd-2020-15126</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2020-15126"/>
  </entry>
</feed>
