Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2026-18709 An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepa… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.4 CVE-2026-18708 An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be exe… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.6 CVE-2026-18706 An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management command… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18705 An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a … No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18704 An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against co… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.4 CVE-2026-18702 An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affe… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18701 An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpect… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18700 An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used … No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18699 An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unex… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-18698 An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec… No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-18697 An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-18696 An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definiti… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-18695 An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user … No fix yet Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-18694 An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry … No fix yet Fix from $4,9002026-08-11 HIGH 7.6 CVE-2026-18693 An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data str… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-18692 An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal ref… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-18691 An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-18690 An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18688 An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18687 MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-15426 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-73218 Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-73217 Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to repla… No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-71398 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of … No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-71362 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul… No fix yet Fix from $5,7502026-08-11 HIGH 8.2 CVE-2026-48771 ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48416 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi… No fix yet Fix from $4,9002026-08-11 HIGH 7.6 CVE-2026-48415 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker coul… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-48414 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious… No fix yet Fix from $4,9002026-08-11 HIGH 8.7 CVE-2026-48413 Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious… No fix yet Fix from $4,9002026-08-11