Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.7 CVE-2026-13078 A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that e… MongoDB No fix yet Fix from $1,9502026-07-22 HIGH 7.1 CVE-2026-13077 A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pi… MongoDB No fix yet Fix from $1,9502026-07-22 MEDIUM 6.5 CVE-2026-13075 An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusio… MongoDB No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-13076 An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data typ… MongoDB No fix yet Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-13074 An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the await… MongoDB No fix yet Fix from $1,6002026-07-22 HIGH 8.1 CVE-2026-13072 When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline pro… MongoDB Mitigation only Fix from $1,9502026-07-22 MEDIUM 6.5 CVE-2026-13071 An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side… MongoDB No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2025-7259 An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This … MongoDB Mitigation only Fix from $1,6002025-07-07 MEDIUM 6.8 CVE-2021-20327 A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerab… Libmongocrypt Mitigation only Fix from $1,6002021-02-25 MEDIUM 5.3 CVE-2019-2388 In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops … Ops Manager Mitigation only Fix from $1,6002020-05-13 HIGH 7.0 CVE-2017-2665 The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file… MongoDB Mitigation only Fix from $1,9502018-07-06 HIGH 7.5 CVE-2017-14227 In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at… MongoDB Mitigation only Fix from $1,9502017-09-09 HIGH 7.5 CVE-2016-3104 mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termin… MongoDB Mitigation only Fix from $1,9502017-04-14 MEDIUM 6.5 CVE-2013-3969EPSS 10% The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitiali… MongoDB Mitigation only Fix from $1,6002013-10-01 MEDIUM 6.5 CVE-2013-4650 MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of … MongoDB Mitigation only Fix from $1,6002013-07-04