Vulnerability index

Browse CVEs

158 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-12893 Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Exten… MongoDB 7.0.26 / 8.0.16+ Fix from $1,6002025-11-25 MEDIUM 5.5 CVE-2025-12657 The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later re… MongoDB 7.0.22 / 8.0.10+ Fix from $1,6002025-11-03 MEDIUM 6.5 CVE-2025-11979 An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issu… MongoDB 7.0.25 / 8.0.15+ Fix from $1,6002025-10-20 HIGH 7.5 CVE-2025-11695 When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions p… Rust Driver 3.2.5+ Fix from $1,9502025-10-13 MEDIUM 6.5 CVE-2025-10061 An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect h… MongoDB 6.0.25 / 7.0.22+ Fix from $1,6002025-09-05 HIGH 7.5 CVE-2025-10060 MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure… MongoDB 6.0.25 / 7.0.22+ Fix from $1,9502025-09-05 MEDIUM 6.5 CVE-2025-10059 An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is … MongoDB 6.0.24 / 7.0.18+ Fix from $1,6002025-09-05 MEDIUM 6.5 CVE-2025-7259 An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This … MongoDB Mitigation only Fix from $1,6002025-07-07 HIGH 7.5 CVE-2025-6714 MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when … MongoDB 6.0.23 / 7.0.20+ Fix from $1,9502025-07-07 MEDIUM 6.5 CVE-2025-6713 An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of th… MongoDB 6.0.22 / 7.0.19+ Fix from $1,6002025-07-07 MEDIUM 6.5 CVE-2025-6712 MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to ineffic… MongoDB 8.0.10+ Fix from $1,6002025-07-07 HIGH 8.8 CVE-2025-6706 An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not h… MongoDB 6.0.21 / 7.0.17+ Fix from $1,9502025-06-26 HIGH 7.5 CVE-2025-6709 The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC… MongoDB 6.0.21 / 7.0.17+ Fix from $1,9502025-06-26 HIGH 7.5 CVE-2025-6710 MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted leve… MongoDB 6.0.21 / 7.0.17+ Fix from $1,9502025-06-26 MEDIUM 5.4 CVE-2025-6707 Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administra… MongoDB 5.0.31 / 6.0.24+ Fix from $1,6002025-06-26 CRITICAL 9.8 CVE-2025-3085 A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status… MongoDB 5.0.31 / 6.0.20+ Fix from $2,3002025-04-01 MEDIUM 6.5 CVE-2025-3084 When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router s… MongoDB 5.0.31 / 6.0.20+ Fix from $1,6002025-04-01 HIGH 7.5 CVE-2025-3083 Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticate… MongoDB 5.0.31 / 6.0.20+ Fix from $1,9502025-04-01 MEDIUM 5.4 CVE-2025-3082 A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlyi… MongoDB 5.0.31 / 6.0.20+ Fix from $1,6002025-04-01 HIGH 7.5 CVE-2025-0755 The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result … Libbson 1.27.5 / 7.0.16+ Fix from $1,9502025-03-18 HIGH 7.8 CVE-2025-1755 MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's syste… Compass 1.42.1+ Fix from $1,9502025-02-27 HIGH 7.8 CVE-2025-1756 mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with e… Mongosh 2.3.0+ Fix from $1,9502025-02-27 HIGH 8.8 CVE-2025-1692 The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to p… Mongosh 2.3.9+ Fix from $1,9502025-02-27 MEDIUM 6.8 CVE-2025-1693 The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject cont… Mongosh 2.3.9+ Fix from $1,6002025-02-27 MEDIUM 6.5 CVE-2025-1691 The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the a… Mongosh 2.3.9+ Fix from $1,6002025-02-27 HIGH 8.1 CVE-2024-10921 An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that const… MongoDB 5.0.30 / 6.0.19+ Fix from $1,9502024-11-14 MEDIUM 6.5 CVE-2024-8305 prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause… MongoDB 6.0.17 / 7.0.13+ Fix from $1,6002024-10-21 CRITICAL 9.8 CVE-2024-8654 MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta… MongoDB after 6.0.3 Fix from $2,3002024-09-10 MEDIUM 6.7 CVE-2024-8207 In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible fo… MongoDB 5.0.14 / 6.0.3+ Fix from $1,6002024-08-27 MEDIUM 5.3 CVE-2024-6384 "Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoD… MongoDB 6.0.16 / 7.0.11+ Fix from $1,6002024-08-13