Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2025-12893
Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Exten…
MongoDB
7.0.26 / 8.0.16+
MEDIUM 5.5
CVE-2025-12657
The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later re…
MongoDB
7.0.22 / 8.0.10+
MEDIUM 6.5
CVE-2025-11979
An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issu…
MongoDB
7.0.25 / 8.0.15+
HIGH 7.5
CVE-2025-11695
When tlsInsecure=False appears in a connection string, certificate validation is disabled.
This vulnerability affects MongoDB Rust Driver versions p…
Rust Driver
3.2.5+
MEDIUM 6.5
CVE-2025-10061
An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect h…
MongoDB
6.0.25 / 7.0.22+
HIGH 7.5
CVE-2025-10060
MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially causing an invariant failure…
MongoDB
6.0.25 / 7.0.22+
MEDIUM 6.5
CVE-2025-10059
An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is …
MongoDB
6.0.24 / 7.0.18+
MEDIUM 6.5
CVE-2025-7259
An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, which may result to crash. This …
MongoDB
Mitigation only
HIGH 7.5
CVE-2025-6714
MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when …
MongoDB
6.0.23 / 7.0.20+
MEDIUM 6.5
CVE-2025-6713
An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of th…
MongoDB
6.0.22 / 7.0.19+
MEDIUM 6.5
CVE-2025-6712
MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This condition is linked to ineffic…
MongoDB
8.0.10+
HIGH 8.8
CVE-2025-6706
An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not h…
MongoDB
6.0.21 / 7.0.17+
HIGH 7.5
CVE-2025-6709
The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC…
MongoDB
6.0.21 / 7.0.17+
HIGH 7.5
CVE-2025-6710
MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted leve…
MongoDB
6.0.21 / 7.0.17+
MEDIUM 5.4
CVE-2025-6707
Under certain conditions, an authenticated user request may execute with stale privileges following an intentional change by an authorized administra…
MongoDB
5.0.31 / 6.0.24+
CRITICAL 9.8
CVE-2025-3085
A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status…
MongoDB
5.0.31 / 6.0.20+
MEDIUM 6.5
CVE-2025-3084
When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router s…
MongoDB
5.0.31 / 6.0.20+
HIGH 7.5
CVE-2025-3083
Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticate…
MongoDB
5.0.31 / 6.0.20+
MEDIUM 5.4
CVE-2025-3082
A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlyi…
MongoDB
5.0.31 / 6.0.20+
HIGH 7.5
CVE-2025-0755
The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result …
Libbson
1.27.5 / 7.0.16+
HIGH 7.8
CVE-2025-1755
MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's syste…
Compass
1.42.1+
HIGH 7.8
CVE-2025-1756
mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with e…
Mongosh
2.3.0+
HIGH 8.8
CVE-2025-1692
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to p…
Mongosh
2.3.9+
MEDIUM 6.8
CVE-2025-1693
The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject cont…
Mongosh
2.3.9+
MEDIUM 6.5
CVE-2025-1691
The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the a…
Mongosh
2.3.9+
HIGH 8.1
CVE-2024-10921
An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that const…
MongoDB
5.0.30 / 6.0.19+
MEDIUM 6.5
CVE-2024-8305
prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause…
MongoDB
6.0.17 / 7.0.13+
CRITICAL 9.8
CVE-2024-8654
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation sta…
MongoDB
after 6.0.3
MEDIUM 6.7
CVE-2024-8207
In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible fo…
MongoDB
5.0.14 / 6.0.3+
MEDIUM 5.3
CVE-2024-6384
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoD…
MongoDB
6.0.16 / 7.0.11+