<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 03:30:11 +0000</lastBuildDate>
    <item>
      <title>cnvd-2020-44896</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-44896</link>
      <description>cnvd-2020-44896</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-44896</guid>
    </item>
    <item>
      <title>EUVD-2026-42684</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42684</link>
      <description>EUVD-2026-42684</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42684</guid>
    </item>
    <item>
      <title>fkie_cve-2020-15126</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-15126</link>
      <description>&lt;p&gt;In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In parser-server from version 3.5.0 and before 4.3.0, an authenticated user using the viewer GraphQL query can by pass all read security on his User object and can also by pass all objects linked via relation or Pointer on his User object.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-15126</guid>
    </item>
    <item>
      <title>GHSA-236h-rqv8-8q73 — GraphQL: Security breach on Viewer query</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-236h-rqv8-8q73</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: parse-server&lt;/p&gt;
&lt;p&gt;### Impact
An authenticated user using the viewer GraphQL query can bypass all read security on his User object and can also bypass all objects linked via relation or Pointer on his User object.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability has been patched in Parse Server 4.3.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
No&lt;/p&gt;
&lt;p&gt;### References
See [commit 78239ac](https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa) for details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: parse-server&lt;/p&gt;
&lt;p&gt;### Impact
An authenticated user using the viewer GraphQL query can bypass all read security on his User object and can also bypass all objects linked via relation or Pointer on his User object.&lt;/p&gt;
&lt;p&gt;### Patches
This vulnerability has been patched in Parse Server 4.3.0.&lt;/p&gt;
&lt;p&gt;### Workarounds
No&lt;/p&gt;
&lt;p&gt;### References
See [commit 78239ac](https://github.com/parse-community/parse-server/commit/78239ac9071167fdf243c55ae4bc9a2c0b0d89aa) for details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-236h-rqv8-8q73</guid>
    </item>
    <item>
      <title>gsd-2020-15126</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-15126</link>
      <description>gsd-2020-15126</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-15126</guid>
    </item>
  </channel>
</rss>
