Vulnerability index

Browse CVEs

158 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MongoDB MEDIUM 5.4
CVE-2025-12893

Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Exten…

Fix: 7.0.26 / 8.0.16+
Fix from $1,600 2025-11-25
MongoDB MEDIUM 5.5
CVE-2025-12657

The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later re…

Fix: 7.0.22 / 8.0.10+
Fix from $1,600 2025-11-03
MongoDB MEDIUM 6.5
CVE-2025-11979

An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issu…

Fix: 7.0.25 / 8.0.15+
Fix from $1,600 2025-10-20
Rust Driver HIGH 7.5
CVE-2025-11695

When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions p…

Fix: 3.2.5+
Fix from $1,950 2025-10-13
MongoDB MEDIUM 6.5
CVE-2025-10061

An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect h…

Fix: 6.0.25 / 7.0.22+
Fix from $1,600 2025-09-05
MongoDB HIGH 7.5
CVE-2025-10060

MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure…

Fix: 6.0.25 / 7.0.22+
Fix from $1,950 2025-09-05
MongoDB MEDIUM 6.5
CVE-2025-10059

An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is …

Fix: 6.0.24 / 7.0.18+
Fix from $1,600 2025-09-05
MongoDB MEDIUM 6.5
CVE-2025-7259

An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This …

Mitigation only
Fix from $1,600 2025-07-07
MongoDB HIGH 7.5
CVE-2025-6714

MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when …

Fix: 6.0.23 / 7.0.20+
Fix from $1,950 2025-07-07
MongoDB MEDIUM 6.5
CVE-2025-6713

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of th…

Fix: 6.0.22 / 7.0.19+
Fix from $1,600 2025-07-07
MongoDB MEDIUM 6.5
CVE-2025-6712

MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to ineffic…

Fix: 8.0.10+
Fix from $1,600 2025-07-07
MongoDB HIGH 8.8
CVE-2025-6706

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not h…

Fix: 6.0.21 / 7.0.17+
Fix from $1,950 2025-06-26
MongoDB HIGH 7.5
CVE-2025-6709

The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC…

Fix: 6.0.21 / 7.0.17+
Fix from $1,950 2025-06-26
MongoDB HIGH 7.5
CVE-2025-6710

MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted leve…

Fix: 6.0.21 / 7.0.17+
Fix from $1,950 2025-06-26
MongoDB MEDIUM 5.4
CVE-2025-6707

Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administra…

Fix: 5.0.31 / 6.0.24+
Fix from $1,600 2025-06-26
MongoDB CRITICAL 9.8
CVE-2025-3085

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…

Fix: 5.0.31 / 6.0.20+
Fix from $2,300 2025-04-01
MongoDB MEDIUM 6.5
CVE-2025-3084

When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router s…

Fix: 5.0.31 / 6.0.20+
Fix from $1,600 2025-04-01
MongoDB HIGH 7.5
CVE-2025-3083

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticate…

Fix: 5.0.31 / 6.0.20+
Fix from $1,950 2025-04-01
MongoDB MEDIUM 5.4
CVE-2025-3082

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlyi…

Fix: 5.0.31 / 6.0.20+
Fix from $1,600 2025-04-01
Libbson HIGH 7.5
CVE-2025-0755

The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result …

Fix: 1.27.5 / 7.0.16+
Fix from $1,950 2025-03-18
Compass HIGH 7.8
CVE-2025-1755

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's syste…

Fix: 1.42.1+
Fix from $1,950 2025-02-27
Mongosh HIGH 7.8
CVE-2025-1756

mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with e…

Fix: 2.3.0+
Fix from $1,950 2025-02-27
Mongosh HIGH 8.8
CVE-2025-1692

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to p…

Fix: 2.3.9+
Fix from $1,950 2025-02-27
Mongosh MEDIUM 6.8
CVE-2025-1693

The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject cont…

Fix: 2.3.9+
Fix from $1,600 2025-02-27
Mongosh MEDIUM 6.5
CVE-2025-1691

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the a…

Fix: 2.3.9+
Fix from $1,600 2025-02-27
MongoDB HIGH 8.1
CVE-2024-10921

An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that const…

Fix: 5.0.30 / 6.0.19+
Fix from $1,950 2024-11-14
MongoDB MEDIUM 6.5
CVE-2024-8305

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause…

Fix: 6.0.17 / 7.0.13+
Fix from $1,600 2024-10-21
MongoDB CRITICAL 9.8
CVE-2024-8654

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…

Fix: after 6.0.3
Fix from $2,300 2024-09-10
MongoDB MEDIUM 6.7
CVE-2024-8207

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible fo…

Fix: 5.0.14 / 6.0.3+
Fix from $1,600 2024-08-27
MongoDB MEDIUM 5.3
CVE-2024-6384

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoD…

Fix: 6.0.16 / 7.0.11+
Fix from $1,600 2024-08-13