Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.7
CVE-2026-13078
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e…
MongoDB
No fix yet
HIGH 7.1
CVE-2026-13077
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pi…
MongoDB
No fix yet
MEDIUM 6.5
CVE-2026-13075
An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio…
MongoDB
No fix yet
MEDIUM 6.5
CVE-2026-13076
An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ…
MongoDB
No fix yet
MEDIUM 5.3
CVE-2026-13074
An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await…
MongoDB
No fix yet
HIGH 8.1
CVE-2026-13072
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro…
MongoDB
Mitigation only
MEDIUM 6.5
CVE-2026-13071
An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side…
MongoDB
No fix yet
MEDIUM 6.5
CVE-2025-7259
An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This …
MongoDB
Mitigation only
MEDIUM 6.8
CVE-2021-20327
A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerab…
Libmongocrypt
Mitigation only
MEDIUM 5.3
CVE-2019-2388
In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops …
Ops Manager
Mitigation only
HIGH 7.0
CVE-2017-2665
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…
MongoDB
Mitigation only
HIGH 7.5
CVE-2017-14227
In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at…
MongoDB
Mitigation only
HIGH 7.5
CVE-2016-3104
mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termin…
MongoDB
Mitigation only
MEDIUM 6.5
CVE-2013-3969EPSS 10%
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitiali…
MongoDB
Mitigation only
MEDIUM 6.5
CVE-2013-4650
MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of …
MongoDB
Mitigation only