Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MongoDB HIGH 7.7
CVE-2026-13078

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e…

No fix yet
Fix from $1,950 2026-07-22
MongoDB HIGH 7.1
CVE-2026-13077

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pi…

No fix yet
Fix from $1,950 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13075

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13076

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 5.3
CVE-2026-13074

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await…

No fix yet
Fix from $1,600 2026-07-22
MongoDB HIGH 8.1
CVE-2026-13072

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…

Mitigation only
Fix from $1,950 2026-07-22
MongoDB MEDIUM 6.5
CVE-2026-13071

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side…

No fix yet
Fix from $1,600 2026-07-22
MongoDB MEDIUM 6.5
CVE-2025-7259

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This …

Mitigation only
Fix from $1,600 2025-07-07
Libmongocrypt MEDIUM 6.8
CVE-2021-20327

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerab…

Mitigation only
Fix from $1,600 2021-02-25
Ops Manager MEDIUM 5.3
CVE-2019-2388

In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops …

Mitigation only
Fix from $1,600 2020-05-13
MongoDB HIGH 7.0
CVE-2017-2665

The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…

Mitigation only
Fix from $1,950 2018-07-06
MongoDB HIGH 7.5
CVE-2017-14227

In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at…

Mitigation only
Fix from $1,950 2017-09-09
MongoDB HIGH 7.5
CVE-2016-3104

mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termin…

Mitigation only
Fix from $1,950 2017-04-14
MongoDB MEDIUM 6.5
CVE-2013-3969EPSS 10%

The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitiali…

Mitigation only
Fix from $1,600 2013-10-01
MongoDB MEDIUM 6.5
CVE-2013-4650

MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of …

Mitigation only
Fix from $1,600 2013-07-04